Req #75755 [Com]: MySQLi should provide an escape function for use in MATCH...AGAINST
| From: | spam2 at rhsoft dot net | Date: | Wed, 03 Jan 2018 16:46:27 +0000 |
| Subject: | Req #75755 [Com]: MySQLi should provide an escape function for use in MATCH...AGAINST | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-213365@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75755&edit=1
ID: 75755
Comment by: spam2 at rhsoft dot net
Reported by: php4fan at gmail dot com
Summary: MySQLi should provide an escape function for use in
MATCH...AGAINST
Status: Open
Type: Feature/Change Request
Package: MySQLi related
PHP Version: 7.1.12
Block user comment: N
Private report: N
New Comment:
http://php.net/manual/en/mysqli.real-escape-string.php
Previous Comments:
------------------------------------------------------------------------
[2018-01-03 16:41:11] php4fan at gmail dot com
Description:
------------
Say you have a string $someword and you need to use it within a query like:
"SELECT whatever where MATCH(whatever) AGAINST('+$someword +someotherword' IN BOOLEAN
MODE)"
You need to properly escape certain characters in $someword so that you don't get syntax errors
in the boolean search expression. I know I'm being sloppy at defining what needs to be done.
Actually I'm pretty sure there are different kinds of escaping you would need for different use
cases, but it's certainly possible to define them unambiguously.
Expected: there should be methods in the MySQLi class for this.
Observed: you have to write your own code, and you'll almost certainly get it wrong; or
you'll have to find some 3rd party libraries, which is pathetic.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75755&edit=1