note 59382 added to function.set-magic-quotes-runtime

From: Date: Mon, 05 Dec 2005 13:08:46 +0000
Subject: note 59382 added to function.set-magic-quotes-runtime
Groups: php.notes 
Request: Send a blank email to php-notes+get-99588@lists.php.net to get a copy of this message
magic_quotes_runtime is pretty much useless most of the time and is a good practice to turn it OFF in your scripts when is not needed, this because you might lose some time dealing with errors until you realize this feature is ON in your server. magic_quotes_runtime is useful mostly when moving data from text files to databases or viceversa, this is needed because storing unescaped strings in a database will cause all kinds of trouble as soon as you store something containing an apostrophe or other special character, and can also leave you open to SQL injection security vulnerabilities. You can achieve similar functionality by using addslashes() with variables which content is gathered from external sources. Also, you can manually clean up unescaped strings with magic_quotes_runtime in your script you can use the stripslashes() function. For example, the next snippet will clean up an array of strings (maybe from DB) unescaped with addslashes() or magic_quotes_runtime: <?PHP if(!empty($db_array)){ foreach($_db_array as $i => $v){ $db_array[$i] = stripslashes($v); } } ?> ---- Mel http://www.webhostingjournal.net/ ---- Manual Page -- http://www.php.net/manual/en/function.set-magic-quotes-runtime.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+59382 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=useless Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=non-english Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes&reason=already+in+docs Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59382&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+59382&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#99588) next »