Re: 8.1.4: Who says "PHP deprecated addslashes since 4.0"? - Mailing list pgsql-general

From Tom Lane
Subject Re: 8.1.4: Who says "PHP deprecated addslashes since 4.0"?
Date
Msg-id 7747.1148526331@sss.pgh.pa.us
Whole thread Raw
In response to 8.1.4: Who says "PHP deprecated addslashes since 4.0"?  (ljb <ljb220@mindspring.com>)
List pgsql-general
ljb <ljb220@mindspring.com> writes:
> |  addslashes() or magic_quotes. We note that these tools have been deprecated
> |  by the PHP group since version 4.0.

> Can anyone provide a source for the statement?

I'm not going to put words in Josh's mouth about where he got that from,
but anyone who reads all of the comments at
http://us3.php.net/manual/en/function.addslashes.php
ought to come away suitably unimpressed with the security of that
function.

            regards, tom lane

pgsql-general by date:

Previous
From: Tom Lane
Date:
Subject: Re: recompliing c-language functions with new releases of postgres
Next
From: "Chris Velevitch"
Date:
Subject: Re: How to estimate disk space