Re: Re: policy on magic quotes

From: Date: Tue, 08 Feb 2005 09:06:42 +0000
Subject: Re: Re: policy on magic quotes
References: 1 2 3 4 5  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-36043@lists.php.net to get a copy of this message
As far as I know no packages actually modify the contents of $_GET/$_POST, they just read the data and clean it locally if necessary. If they return a filtered version of $_GET etc. then it should be indicated in the documentation.. Regards Alan > One problem could arise if 2 required packages clean the magic quotes. > I give one example from myself, in the Console_Extend proposal I > currently develop. > When arguments inquiry is made over HTTP, as the POST and COOKIE are used, > a first cleanup is done case this :( magic quotes :( ar on. > Not yet implemented but the stuff will certainly need some kind of > authentification and the package Auth will be used. > Problem occurs as Auth is doing also: > $this->username = (get_magic_quotes_gpc() == 1 ? > stripslashes($this->post[$this->_postUsername]) : > $this->post[$this->_postUsername]); > $this->password = (get_magic_quotes_gpc() == 1 ? > stripslashes($this->post[$this->_postPassword]) : > $this->post[$this->_postPassword] ); > > We risk a double stripslashes() what is almost no risk, especially here, > but could in dealing with very special strings to unexpected result. > As to now, it's up to the package requiring the second package to take > care of not cleaning what the required package cleans from itself. > PEAR could eventually offer a common cleanup, so the packages don't test > get_magic_quotes_gpc() but say: PEAR::isCleanMagicQuotesGPC() and > PEAR::makeCleanMagicQuotesGPC() so to avoid concurent cleanings. > à+ -- Alan Knowles <alan@akbkhome.com>

« previous php.pear.dev (#36043) next »