[Fwd: Re: [PEAR-DEV] Re: magic_quotes_runtime and portability]
| From: | Alan Knowles | Date: | Sat, 22 Nov 2003 01:31:11 +0000 |
| Subject: | [Fwd: Re: [PEAR-DEV] Re: magic_quotes_runtime and portability] | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-23808@lists.php.net to get a copy of this message | ||
magic_quotes is an absolute pig ear for compatibility - the amount of
code needed to fix the mess it causes is disproportiate to the benefit
it gives..
As far as I can see packages that need to quote data (eg.
databases/shell scripts) should always assume the data is 'dirty'.. and
do their own escaping/quoting.
_Applications_ that use PEAR packages have the responsibility, to
determine what is the valid state of magic_quotes and,
unescape/stripslashes data before sending to a pear package if they even
permit magic_quotes to be on...
Thoughts....
Regards
Alan
Mehdi Achour wrote:
Hi Greg, done (#279) didou-- Can you help out? Need Consulting Services or Know of a Job? http://www.akbkhome.comHi didou, Can you open a bug for the PEAR package, and paste in the exact error? This will help determine the fix. I've never tested anything with magic_quotes_runtime on, would be good to do that. Greg Mehdi Achour wrote:Hi ! We've just installed PEAR on one of our production server and we had some problems running PEAR::Info. The problem was corrected by setting magic_quotes_runtime to 0 at runtime (using set_magic_quotes_runtime()). Shouldn't the PEAR core be safe of this kind of problems ? (Actually the problem was located at PEAR/Registry.php:339 where the script tried to unserialize the packages infos) didou