RE: [PHP-DB] Fixed Quote Marks in Inputs
| From: | Rick Emery | Date: | Fri, 04 Jan 2002 20:10:50 +0000 |
| Subject: | RE: [PHP-DB] Fixed Quote Marks in Inputs | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-15408@lists.php.net to get a copy of this message | ||
Another option is to use PHP's addslashes() and stripslashes() functions.
These will add/remove slashes in front of quotes to make them database
friendly.
-----Original Message-----
From: Jonathan Hilgeman [mailto:JHilgeman@ecx.com]
Sent: Friday, January 04, 2002 2:05 PM
To: php-db@lists.php.net
Subject: [PHP-DB] Fixed Quote Marks in Inputs
I finally came up with a reliable solution that I can use when I'm dealing
with form inputs that can contain quote marks (single or double quotes). To
store quote marks, you can str_replace them with their HTML code
equivalents. For single quote marks, this is ', and for double quote
marks it's "
So before I insert any input into my database, I run my below function on
all the data:
// Replace quotes with their ' and " equivalents
function PrepareQuotes($Var)
{
$Var = str_replace("'","'",$Var);
$Var = str_replace('"',""",$Var);
return $Var;
}
Hope this helps someone else.
- Jonathan
--
PHP Database Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
For additional commands, e-mail: php-db-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net