That's it. Repeat for getvars, cookies, and the like.
No worries any longer. They're safe for queries (all the ' and " have been escaped). They can be printed out again, without having to worry about javascript attacks.
Hey, if you like, you can change it to nl2br(htmlentities... and you won't have to do any processing when outputing user information again!
Oh, and the unset() forces you to use the appropriate 'globals', ie. either $HTTP_XXX_VARS or $_XXX to access incoming variables. Much easier to replace if they decide to change the handling again. After all, PHP 5 is due in the second quartal of 2003...