Re: Re: policy on magic quotes

From: Date: Tue, 08 Feb 2005 08:45:57 +0000
Subject: Re: Re: policy on magic quotes
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-36041@lists.php.net to get a copy of this message
Hello to magic quotes dealers. Go away Ruby on Rails hijackers (thanks Daniel O'Connor) Alan Knowles wrote:
$var = get_magic_quotes_gpc() ? stripslashes($var) : $var;
Only code that deals directly with $_GET/$_POST etc should do anything like the above. - since most of PEAR is libraries and do not directly deal with this, It does not affect most packages. The only exceptions I know of are: Pager - not sure what it does Quickforms - handles it AFAIK Auth - handles it AFAIK. Generally If the packages deals directly with input, I would presume it should handle it.
One problem could arise if 2 required packages clean the magic quotes. I give one example from myself, in the Console_Extend proposal I currently develop. When arguments inquiry is made over HTTP, as the POST and COOKIE are used, a first cleanup is done case this :( magic quotes :( ar on. Not yet implemented but the stuff will certainly need some kind of authentification and the package Auth will be used. Problem occurs as Auth is doing also: $this->username = (get_magic_quotes_gpc() == 1 ? stripslashes($this->post[$this->_postUsername]) : $this->post[$this->_postUsername]); $this->password = (get_magic_quotes_gpc() == 1 ? stripslashes($this->post[$this->_postPassword]) : $this->post[$this->_postPassword] ); We risk a double stripslashes() what is almost no risk, especially here, but could in dealing with very special strings to unexpected result. As to now, it's up to the package requiring the second package to take care of not cleaning what the required package cleans from itself. PEAR could eventually offer a common cleanup, so the packages don't test get_magic_quotes_gpc() but say: PEAR::isCleanMagicQuotesGPC() and PEAR::makeCleanMagicQuotesGPC() so to avoid concurent cleanings. à+ -- bertrand Gugger (toggg)

« previous php.pear.dev (#36041) next »