3 ms·
htmlspecialchars() is for html sanitation. For the sql in insert.php you will want mysql_real_escape_string(). insert.php writes to the database. You may want
by Tangaroa 15y ago
htmlspecialchars() is for html sanitation. For the sql in insert.php you will want mysql_real_escape_string().
insert.php writes to the database. You may want to wrap that inside some kind of session checking so that only logged-in users are allowed to run the insert. As it is now, anybody could send parameters to the script and it would run an insert.
You may also want to create some protection against a double-insert.
"break" is repeated in index.php characterData() case TITLE. This won't cause any problems but it reminds me that PHP lets you say "break 2" to break out of two layers of looping, if you ever need to do that.