doujiyan0031 2011-04-24 13:07
浏览 42
已采纳

php转义用户输入以在html中显示

php page1 --> below bit is pure html:

<form action="page2.php" method="post">
<input type="text" name="name" id="name">
-----------submit button, end form --etc.--------------

php page2 (and yes i have intended to stuff the text input from page1 into a hidden input in page2):

foreach($_REQUEST as $key=>$value) 
{
     $value = htmlspecialchars(strip_tags(stripslashes($value))); //attempt to cleanse the data before displaying
}
echo "<p><input type='hidden' id='name' name='name' value='".$_REQUEST['name']."'/>".$_REQUEST['name']."</p>";

The problem is that the output on page 2 is not producing w3 compliant html if the user enters input with quotes such as John O'Brien, the html becomes:

<p><input type='hidden' id='email' name='email' value='John O'Brien'/>John O'Brien</p>

I would also like to be able to produce w3 compliant html for any bad input data such as: j'o/h s"m,ith

Any help is appreciated!

  • 写回答

4条回答 默认 最新

  • douyao1994 2011-04-24 13:32
    关注
    • First of all, not your code, nor any of ones posted above will ever work. For the very silly reason.
    • Next, I am kinda fixated on preserving user input exactly as is. Why delete something might be important?
    • Third, hidden values should be urlencoded I believe, rather than htmlencoded

    so

    $FORM = array();
    foreach($_POST as $key =>$value) {
        if(get_magic_quotes_gpc()) {
            $value = stripslashes($value);
        }
        $FORM[$key] = htmlspecialchars($value,ENT_QUOTES);
    }
    echo "<p><input type='hidden' id='name' name='name' value='".$FORM['name']."'/>".
              $FORM['name'].
         "</p>";
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(3条)

报告相同问题?

悬赏问题

  • ¥20 怎么用dlib库的算法识别小麦病虫害
  • ¥15 华为ensp模拟器中S5700交换机在配置过程中老是反复重启
  • ¥15 java写代码遇到问题,求帮助
  • ¥15 uniapp uview http 如何实现统一的请求异常信息提示?
  • ¥15 有了解d3和topogram.js库的吗?有偿请教
  • ¥100 任意维数的K均值聚类
  • ¥15 stamps做sbas-insar,时序沉降图怎么画
  • ¥15 买了个传感器,根据商家发的代码和步骤使用但是代码报错了不会改,有没有人可以看看
  • ¥15 关于#Java#的问题,如何解决?
  • ¥15 加热介质是液体,换热器壳侧导热系数和总的导热系数怎么算