Re: cvs: pear /Structures_DataGrid/DataGrid/Renderer CSV.php HTMLTable.php

From: Date: Fri, 11 Mar 2005 23:06:21 +0000
Subject: Re: cvs: pear /Structures_DataGrid/DataGrid/Renderer CSV.php HTMLTable.php
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-36658@lists.php.net to get a copy of this message
On Fri, 11 Mar 2005 23:01:06 -0000, Andrew Nagy <asnagy@php.net> wrote: http://cvs.php.net/diff.php/pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php?r1=1.40&r2=1.41&ty=u > Index: pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php > diff -u pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php:1.40 > pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php:1.41 > --- pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php:1.40 Thu Jan 27 15:56:44 > 2005 > +++ pear/Structures_DataGrid/DataGrid/Renderer/HTMLTable.php Fri Mar 11 18:01:05 2005 > @@ -16,14 +16,14 @@ > // | Author: Andrew Nagy <asnagy@webitecture.org> | > // +----------------------------------------------------------------------+ > // > -// $Id: HTMLTable.php,v 1.40 2005/01/27 20:56:44 asnagy Exp $ > +// $Id: HTMLTable.php,v 1.41 2005/03/11 23:01:05 asnagy Exp $ > > require_once 'HTML/Table.php'; > > /** > * Structures_DataGrid_Renderer_HTMLTable Class > * > - * @version $Revision: 1.40 $ > + * @version $Revision: 1.41 $ > * @author Andrew S. Nagy <asnagy@webitecture.org> > * @access public > * @package Structures_DataGrid > @@ -435,7 +435,7 @@ > } > } else { > // Use Record Data > - $content = $row[$column->fieldName]; > + $content = > htmlentities(stripslashes($row[$column->fieldName])); Are you sure you want to stripslashes() here? Is DataGrid addslashing the content somewhere? If it's not, please don't stripslashes as it can quite easily cause loss of information. Whatever data DataGrid is given, it should display it intact. If a user's data has extra slashes, they should deal with it when storing the data. (or before they send it to DataGrid) -- Justin Patrin

« previous php.pear.dev (#36658) next »