Doc #52901 [Fbk->Opn]: addslashes for database queries

From: Date: Tue, 21 Sep 2010 15:10:33 +0000
Subject: Doc #52901 [Fbk->Opn]: addslashes for database queries
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-5098@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=52901&edit=1 ID: 52901 User updated by: johnston dot joshua at gmail dot com Reported by: johnston dot joshua at gmail dot com Summary: addslashes for database queries -Status: Feedback +Status: Open Type: Documentation Problem Package: Documentation problem Operating System: ALL PHP Version: Irrelevant Block user comment: N New Comment: http://php.net/addslashes Under Desc the first two sentences are: Returns a string with backslashes before characters that need to be quoted in database queries etc. These characters are single quote ('), double quote ("), backslash (\) and NUL (the NULL byte). An example use of addslashes() is when you're entering data into a database. For example, to insert the name O'reilly into a database, you will need to escape it. Previous Comments: ------------------------------------------------------------------------ [2010-09-21 17:00:17] philip@php.net Where do you see this? ------------------------------------------------------------------------ [2010-09-21 16:57:01] johnston dot joshua at gmail dot com Description: ------------ Please remove the cruft about using addslashes to escape data for database queries. It gives people the wrong idea. I know it says use mysql_real_escape string right after it, but even the suggestion of using addslashes gives new people the wrong idea. Tell them it's great for escaping strings for use in javascript or something. please! ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/bug.php?id=52901&edit=1

« previous php.doc.bugs (#5098) next »