Re: Re: policy on magic quotes

From: Date: Tue, 08 Feb 2005 09:28:02 +0000
Subject: Re: Re: policy on magic quotes
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-36050@lists.php.net to get a copy of this message
Alan Knowles wrote:
$var = get_magic_quotes_gpc() ? stripslashes($var) : $var;
Only code that deals directly with $_GET/$_POST etc should do anything like the above. - since most of PEAR is libraries and do not directly deal with this, It does not affect most packages. The only exceptions I know of are: Pager - not sure what it does
Pager may use the following two GET/POST values: $_REQUEST[$this->_sessionVar] $_REQUEST[$this->_urlVar] both are cast to int. $_SERVER['QUERY_STRING'] AFAIK is not affected, but I've extensively tested it with magic_quotes_gpc on and off, with magic_quotes_sybase on and off, and there are no problems whatsoever. The html output (i.e. the querystring) is filtered with htmlentities() to prevent XSS attacks. Regards, -- Lorenzo Alberton http://pear.php.net/user/quipo

« previous php.pear.dev (#36050) next »