Re: Escaping queries in php using InterBase
| From: | Yves Glodt | Date: | Wed, 22 Aug 2001 12:42:00 +0000 |
| Subject: | Re: Escaping queries in php using InterBase | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-11650@lists.php.net to get a copy of this message | ||
On Wednesday 22 August 2001 14:34, Patrik Wallstrom wrote:
> On Wed, 22 Aug 2001, Yves Glodt wrote:
> > Hello,
> >
> > I'm in trouble with my current project which uses Interbase as
> > backend. (php.ini: magic_quotes_sybase = On)
> > When I insert a string containing a ', like Beverly D'Angelo,
> > php saves it with two '
> > When I insert it with two ', it gets saved with four '
>
> [...]
>
> I have always wondered why there is no mysql specifig quoting
> functions in php. Here is what I use:
>
> function myslashes($content = "") {
> $content = str_replace("\\","\\\\",$content);
> $content = str_replace("'","\\'",$content);
> return $content;
> }
>
> I guess Interbase also uses backslash for quoting?
Unforunately not!
You must use ' for escaping.
But now rethinking, some str_replace("''","'",$var); before
displaying
the string should do it.
thank you,
yves