’htmlspecialchars’,//对get,post数据进行htmlspecialchars过滤,这样也不行。
xxxxxx这样的js代码时,需要手动进行htmlspecialchars过滤。
<?<span php </span><span class</span> AdsModel <span extends</span><span CommonModel { </span><span //</span><span 自动验证设置</span> <span protected</span> <span $_validate</span> = <span array</span><span ( ); </span><span //</span><span 自动填充设置</span> <span protected</span> <span $_auto</span> = <span array</span><span ( </span><span array</span>('ad_code','getCode',1,'callback'), <span //</span><span 对name字段在新增的时候回调getName方法</span> <span ); </span><span protected</span> <span function</span> getCode(<span $ad_code</span><span ){ </span><span return</span> <span htmlspecialchars</span>(<span $ad_code</span><span ); } }</span>