Re: Re: policy on magic quotes
| From: | Alan Knowles | Date: | Tue, 08 Feb 2005 09:06:42 +0000 |
| Subject: | Re: Re: policy on magic quotes | ||
| References: | 1 2 3 4 5 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-36043@lists.php.net to get a copy of this message | ||
As far as I know no packages actually modify the contents of
$_GET/$_POST, they just read the data and clean it locally if necessary.
If they return a filtered version of $_GET etc. then it should be
indicated in the documentation..
Regards
Alan
> One problem could arise if 2 required packages clean the magic quotes.
> I give one example from myself, in the Console_Extend proposal I
> currently develop.
> When arguments inquiry is made over HTTP, as the POST and COOKIE are used,
> a first cleanup is done case this :( magic quotes :( ar on.
> Not yet implemented but the stuff will certainly need some kind of
> authentification and the package Auth will be used.
> Problem occurs as Auth is doing also:
> $this->username = (get_magic_quotes_gpc() == 1 ?
> stripslashes($this->post[$this->_postUsername]) :
> $this->post[$this->_postUsername]);
> $this->password = (get_magic_quotes_gpc() == 1 ?
> stripslashes($this->post[$this->_postPassword]) :
> $this->post[$this->_postPassword] );
>
> We risk a double stripslashes() what is almost no risk, especially here,
> but could in dealing with very special strings to unexpected result.
> As to now, it's up to the package requiring the second package to take
> care of not cleaning what the required package cleans from itself.
> PEAR could eventually offer a common cleanup, so the packages don't test
> get_magic_quotes_gpc() but say: PEAR::isCleanMagicQuotesGPC() and
> PEAR::makeCleanMagicQuotesGPC() so to avoid concurent cleanings.
> à+
--
Alan Knowles <alan@akbkhome.com>