Quote:
Originally Posted by EnIgMa1234
Why is it neccessary to clean admincp code?
|
It's just good coding practice to do so. Say for instance you have a moderator or someone whom you allow access to the admin CP (a business partner for instance) and you have a falling out - he/she then injects something nasty theough the AdminCP and BOOM!
Sir Adrian,
ok, i'm learning this, thanks. So after escaping it, if I want to display it in a <textarea> type input box for user to edit it, it's showing as follows:
Quote:
Posted the banner on my myspace profile. Also posted their video on my blog, etc... \r\n\r\nOh yes i did.\r\n\r\nThat\'s what I am talking about. "oh yeah" i said
|
Which is safe, however for display in the textarea, i want it to display as entered which was like this:
Quote:
Posted the banner on my myspace profile. Also posted their video on my blog, etc...
Oh yes i did.
That's what I am talking about. "oh yeah" i said
|
When I display it, I can qet the " to parse correctly, but all the /n/r/n/r i can't get to display correctly. Can you help? Thanks