Re: com web/master: Convert all stripslashes() to use master function strip().: manage/user-notes.php
| From: | Hannes Magnusson | Date: | Thu, 10 May 2012 19:09:38 +0000 |
| Subject: | Re: com web/master: Convert all stripslashes() to use master function strip().: manage/user-notes.php | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-13512@lists.php.net to get a copy of this message | ||
On Thu, May 10, 2012 at 9:02 PM, Daniel P. Brown <danbrown@php.net> wrote:
> Commit: aee9c2bf3d06154619e7f2a4c5478557fa19ee60
> Author: Daniel P. Brown <danbrown@php.net> Thu, 10 May 2012 15:02:27
> -0400
> Parents: ed1c23b85911a6c41ba9346b4d05260a5fa55dbe
> Branches: master
>
> Link:
> http://git.php.net/?p=web/master.git;a=commitdiff;h=aee9c2bf3d06154619e7f2a4c5478557fa19ee60ʫR*øy"
^_5
> ‹u
>
> Log:
> Convert all stripslashes() to use master function strip().
>
> Changed paths:
> M manage/user-notes.php
>
>
> Diff:
> diff --git a/manage/user-notes.php b/manage/user-notes.php
> index bd68fa9..2032cbd 100644
> --- a/manage/user-notes.php
> +++ b/manage/user-notes.php
> @@ -305,10 +305,10 @@ case 'edit':
> $user,
> $id,
> "note {$row['id']} modified in {$row['sect']} by
> $user",
> -
> stripslashes($note)."\n\n--was--\n{$row['note']}\n\nhttp://php.net/manual/en/{$row['sect']}.php"
> +
> strip($note)."\n\n--was--\n{$row['note']}\n\nhttp://php.net/manual/en/{$row['sect']}.php"
> );
> if (addslashes($row["sect"]) != $sect) {
> - note_mail_user($email, "note $id moved from $row[sect] to $sect by notes
> editor $user", "----- Copy of your note below -----\n\n".stripslashes($note));
> + note_mail_user($email, "note $id moved from $row[sect] to $sect by notes
> editor $user", "----- Copy of your note below -----\n\n".strip($note));
> }
> header('Location: user-notes.php?id=' . $id . '&was=' .
> $action);
> exit;
> @@ -318,9 +318,9 @@ case 'edit':
> $note = isset($note) ? $note : addslashes($row['note']);
>
> if ($action == "preview") {
> - echo "<p class=\"notepreview\">",stripslashes($note),
> + echo "<p class=\"notepreview\">",strip($note),
> "<br /><span
> class=\"author\">",date("d-M-Y h:i",$row['ts'])," ",
> - stripslashes($email),"</span></p>";
> + strip($email),"</span></p>";
> }
> ?>
> <form method="post" action="<?= PHP_SELF ?>">
> @@ -335,7 +335,7 @@ case 'edit':
> <td><input type="text" name="email" value="<?=
> escape($email) ?>" size="30" maxlength="80" /></td>
> </tr>
> <tr>
> - <td colspan="2"><textarea name="note" cols="70"
> rows="15"><?= stripslashes(clean($note)) ?></textarea></td>
> + <td colspan="2"><textarea name="note" cols="70"
> rows="15"><?= strip(strip(escape($note))) ?>
strip(strip(escape())) ? That doesn't look correct
-Hannes