php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #44748 php.ini comments on magic_quotes_gpc promote bad practices
Submitted: 2008-04-16 19:34 UTC Modified: 2008-10-26 15:40 UTC
From: johnston dot joshua at gmail dot com Assigned: kalle (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS: any
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: johnston dot joshua at gmail dot com
New email:
PHP Version: OS:

 

 [2008-04-16 19:34 UTC] johnston dot joshua at gmail dot com
Description:
------------
The section at the top related to magic_quotes_gpc suggests addslashes() for database escaping. It should instead say to use your the escaping function that is native to your database extension.


; - magic_quotes_gpc = Off         [Performance]
;     Input data is no longer escaped with slashes so that it can be sent into
;     SQL databases without further manipulation.  Instead, you should use the
;     function addslashes() on each input element you wish to send to a database.


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2008-10-26 15:40 UTC] kalle@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.

I updated PHP 5.3 and PHP 5.2's php.ini-recommeded to reflect this as HEAD is not affected by this.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 15:00:01 2026 UTC