Re: Re: policy on magic quotes
| From: | Lorenzo Alberton | Date: | Tue, 08 Feb 2005 09:28:02 +0000 |
| Subject: | Re: Re: policy on magic quotes | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-36050@lists.php.net to get a copy of this message | ||
Alan Knowles wrote:
Pager may use the following two GET/POST values: $_REQUEST[$this->_sessionVar] $_REQUEST[$this->_urlVar] both are cast to int. $_SERVER['QUERY_STRING'] AFAIK is not affected, but I've extensively tested it with magic_quotes_gpc on and off, with magic_quotes_sybase on and off, and there are no problems whatsoever. The html output (i.e. the querystring) is filtered with htmlentities() to prevent XSS attacks. Regards, -- Lorenzo Alberton http://pear.php.net/user/quipo$var = get_magic_quotes_gpc() ? stripslashes($var) : $var;Only code that deals directly with $_GET/$_POST etc should do anything like the above. - since most of PEAR is libraries and do not directly deal with this, It does not affect most packages. The only exceptions I know of are: Pager - not sure what it does