Hudzilla.org - the homepage of Paul Hudson
Contents > HTML Forms > Handling data Wish List | Report Bug | About Me ]

7.4.3     Magic quotes

This is NOT the latest copy of this book; click here for the latest version.

Owing to the fact that the majority of user input is destined for database entry, PHP has a special php.ini setting called magic_quotes_gpc, which means that PHP will automatically backslashes \ before all quotes and other backslashes for GET, POST, and COOKIE data (GPC) - the equivalent of running the addslashes() function.

This functionality is usually turned on by default, which means that all GPC data coming into your script is safe for database entry, but it also means that if your data is not destined for a database, you need to disable magic quotes in your php.ini file.

Author's Note: I personally prefer to turn magic quotes off and handle the slashes myself, as this leads to much more predictable and easily understood behaviour. Note that changing your execution environment at runtime to enable magic quotes will have no effect on the script, as the variables are already parsed and ready for use by the time your code is executed.





<< 7.4.2 Working around register_globals: import_request_variables()   7.4.4 Data handling summary >>
Table of Contents
Want to see this stuff in print? PHP in a Nutshell takes the core topics covered here, adds in thousands of edits from the editorial team and myself, and combines them to make an unbeatable reference for PHP programmers at all levels.



My latest book has hundreds more tips on how to use PHP, Apache, and MySQL, plus Perl, Python, shell scripts, performance tuning, and more!



Top-right shadow
 
Bottom-left shadow Bottom shadow

Comments from other readers
A PHP User - 16 Oct 2008

Every date is today's date

A PHP User - 16 Oct 2008

automatically backslashes \
did you mean automatically insert backlashes



Add comment
Please note that by posting a comment here you are committing it to the public domain. This is important so that others can make use of your code themselves, and also so that I can incorporate helpful notes directly into the main text. Comments are limited to 2000 characters in length.

If you are reporting an error in the content, please tell me directly.

Your name/email address:
Your comment:
 
Now, in order to verify that you're a real person, please answer this simple question: what is seven plus five?
The answer is:
(please write in
numbers, eg 19)


Top-right shadow
 
Bottom-left shadow Bottom shadow