recess tools should handle magic_quotes
-
Joshua Paine
Ironically, lighthouse seems to have some kind of escaping issue as well, since in my submission there were four backslashes in a row, not two.
-
Kris Jordan
- Tag set to magic, quotes
- State changed from new to open
Need to spend some quality time with magic_quotes turned back on and identify the best path forward for addressing this at the framework level.
Thanks for the report! Leaving this ticket open for the time being.
-
Kris Jordan
- Milestone changed from 0.11.1 to 0.12
- State changed from open to hold
I believe is fixed in a commit you made Joshua with changes to the htacess file. Can you comment?
-
Joshua Paine
The htaccess change fixes it for people running with PHP as an apache module if their server config lets them change PHP settings that way. Some shared hosts (e.g., Bluehost) do PHP as a [Fast]CGI or even suexec, and probably some do the module but don't allow settings that way.
Tools could have some code that checks whether magic quotes is enabled and then 1) un-magic-quotes the input arrays 2) puts a banner at the top of the screen warning that magic quotes shouldn't be on (up to user to config correctly) 3) both
Also a question of whether the framework should instead do (1) for all apps.
-
Kris Jordan
- State changed from hold to open
Thanks for the clarification. Breaking this ticket in two. This ticket will remain in the 0.12 release and provide the stopgap #2 Refactor Controller you've highlighted.
Creating a new ticket for 0.20 to address magic quotes correctly in tools and the framework. Also going to send out an e-mail to the discussion group to discuss framework-level magic quotes support.
-
Kris Jordan
- State changed from open to resolved
Resolved with commit 0067cc7.
Added warning to Recess Tools. Also gained insight on how to handle this at the framework level from the official word on PHP.net:
http://us3.php.net/manual/en/sec...
A workaround at the framework level (that is viciously slow) can be found here: http://us3.php.net/manual/en/sec...
-
Kris Jordan
Also I've removed the random quotes. Just for you, Joshua :)
Please Sign in or create a free account to add a new ticket.
With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.