/*
- Sanitize Input
- Helps reduce security risks and minimalises the possibility of SQL injection.
$string - The string you wish to sanitize before entering into the database.
$level - The level of security:
> 1 = adds slashes to prevent SQL injection
> 2 = adds slashes + htmlspecialchars to turn HTML tags into
HTML entities (eg. <html> becomes <html>)
> 3 = add slashes + strip_tags to remove all HTML tags.
*/
public function sanitizeInput($string, $level = 1) {
switch ($level) {
case 1:
$string = addslashes($string);
break;
case 2:
$string = htmlspecialchars(addslashes($string));
break;
case 3:
$string = strip_tags(addslashes($string));
break;
}
return $string;
}
Comments