Req #75755 [Com]: MySQLi should provide an escape function for use in MATCH...AGAINST

From: Date: Wed, 03 Jan 2018 16:46:27 +0000
Subject: Req #75755 [Com]: MySQLi should provide an escape function for use in MATCH...AGAINST
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213365@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75755&edit=1 ID: 75755 Comment by: spam2 at rhsoft dot net Reported by: php4fan at gmail dot com Summary: MySQLi should provide an escape function for use in MATCH...AGAINST Status: Open Type: Feature/Change Request Package: MySQLi related PHP Version: 7.1.12 Block user comment: N Private report: N New Comment: http://php.net/manual/en/mysqli.real-escape-string.php Previous Comments: ------------------------------------------------------------------------ [2018-01-03 16:41:11] php4fan at gmail dot com Description: ------------ Say you have a string $someword and you need to use it within a query like: "SELECT whatever where MATCH(whatever) AGAINST('+$someword +someotherword' IN BOOLEAN MODE)" You need to properly escape certain characters in $someword so that you don't get syntax errors in the boolean search expression. I know I'm being sloppy at defining what needs to be done. Actually I'm pretty sure there are different kinds of escaping you would need for different use cases, but it's certainly possible to define them unambiguously. Expected: there should be methods in the MySQLi class for this. Observed: you have to write your own code, and you'll almost certainly get it wrong; or you'll have to find some 3rd party libraries, which is pathetic. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75755&edit=1

« previous php.bugs (#213365) next »