note 59382 added to function.set-magic-quotes-runtime
| From: | e-5 at webhostingjournal dot net | Date: | Mon, 05 Dec 2005 13:08:46 +0000 |
| Subject: | note 59382 added to function.set-magic-quotes-runtime | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-99588@lists.php.net to get a copy of this message | ||
magic_quotes_runtime is pretty much useless most of the time and is a good practice to turn it OFF
in your scripts when is not needed, this because you might lose some time dealing with errors until
you realize this feature is ON in your server.
magic_quotes_runtime is useful mostly when moving data from text files to databases or viceversa,
this is needed because storing unescaped strings in a database will cause all kinds of trouble as
soon as you store something containing an apostrophe or other special character, and can also leave
you open to SQL injection security vulnerabilities.
You can achieve similar functionality by using addslashes() with variables which content is gathered
from external sources. Also, you can manually clean up unescaped strings with magic_quotes_runtime
in your script you can use the stripslashes() function.
For example, the next snippet will clean up an array of strings (maybe from DB) unescaped with
addslashes() or magic_quotes_runtime:
<?PHP
if(!empty($db_array)){
foreach($_db_array as $i => $v){
$db_array[$i] = stripslashes($v);
}
}
?>
----
Mel
http://www.webhostingjournal.net/
----
Manual Page -- http://www.php.net/manual/en/function.set-magic-quotes-runtime.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+59382
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+59382&report=yes
Search -- http://master.php.net/manage/user-notes.php