Re: 8.1.4: Who says "PHP deprecated addslashes since 4.0"?

Поиск
Список
Период
Сортировка
От ljb
Тема Re: 8.1.4: Who says "PHP deprecated addslashes since 4.0"?
Дата
Msg-id e55mt4$d4s$1@news.hub.org
обсуждение исходный текст
Ответ на 8.1.4: Who says "PHP deprecated addslashes since 4.0"?  (ljb <ljb220@mindspring.com>)
Ответы Re: 8.1.4: Who says "PHP deprecated addslashes since 4.0"?  (Erik Jones <erik@myemma.com>)
Список pgsql-general
tgl@sss.pgh.pa.us wrote:
> ljb <ljb220@mindspring.com> writes:
>> |  addslashes() or magic_quotes. We note that these tools have been deprecated
>> |  by the PHP group since version 4.0.
>
>> Can anyone provide a source for the statement?
>
> I'm not going to put words in Josh's mouth about where he got that from,
> but anyone who reads all of the comments at
> http://us3.php.net/manual/en/function.addslashes.php
> ought to come away suitably unimpressed with the security of that
> function.

Yes, sorry, I did see those comments, although I don't think they are from
the PHP group themselves.  But I missed the statement on the pg_escape_string
manual page saying "use of this function is recommended instead of
addslashes()". I still think "since version 4.0" is wrong.

В списке pgsql-general по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Status of gist locking in 8.1.3?
Следующее
От: Robert Treat
Дата:
Сообщение: Re: reindexdb program error under PG 8.1.3