Doc #52901 [Fbk->Opn]: addslashes for database queries
| From: | johnston dot joshua at gmail dot com | Date: | Tue, 21 Sep 2010 15:10:33 +0000 |
| Subject: | Doc #52901 [Fbk->Opn]: addslashes for database queries | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-5098@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=52901&edit=1
ID: 52901
User updated by: johnston dot joshua at gmail dot com
Reported by: johnston dot joshua at gmail dot com
Summary: addslashes for database queries
-Status: Feedback
+Status: Open
Type: Documentation Problem
Package: Documentation problem
Operating System: ALL
PHP Version: Irrelevant
Block user comment: N
New Comment:
http://php.net/addslashes
Under Desc the first two sentences are:
Returns a string with backslashes before characters that need to be
quoted in database queries etc. These characters are single quote ('),
double quote ("), backslash (\) and NUL (the NULL byte).
An example use of addslashes() is when you're entering data into a
database. For example, to insert the name O'reilly into a database, you
will need to escape it.
Previous Comments:
------------------------------------------------------------------------
[2010-09-21 17:00:17] philip@php.net
Where do you see this?
------------------------------------------------------------------------
[2010-09-21 16:57:01] johnston dot joshua at gmail dot com
Description:
------------
Please remove the cruft about using addslashes to escape data for
database queries. It gives people the wrong idea.
I know it says use mysql_real_escape string right after it, but even the
suggestion of using addslashes gives new people the wrong idea. Tell
them it's great for escaping strings for use in javascript or something.
please!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=52901&edit=1