Doc #52901 [Opn->Wfx]: addslashes for database queries

From: Date: Wed, 22 Sep 2010 07:58:58 +0000
Subject: Doc #52901 [Opn->Wfx]: addslashes for database queries
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-5108@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=52901&edit=1 ID: 52901 Updated by: aharvey@php.net Reported by: johnston dot joshua at gmail dot com Summary: addslashes for database queries -Status: Open +Status: Wont fix Type: Documentation Problem Package: Documentation problem Operating System: ALL PHP Version: Irrelevant Block user comment: N New Comment: I'd say the text there is already correct: it says to use the DBMS specific escaping function if there is one, but there are database extensions without escaping functions, in which case addslashes() is the correct function to use. Previous Comments: ------------------------------------------------------------------------ [2010-09-21 17:10:33] johnston dot joshua at gmail dot com http://php.net/addslashes Under Desc the first two sentences are: Returns a string with backslashes before characters that need to be quoted in database queries etc. These characters are single quote ('), double quote ("), backslash (\) and NUL (the NULL byte). An example use of addslashes() is when you're entering data into a database. For example, to insert the name O'reilly into a database, you will need to escape it. ------------------------------------------------------------------------ [2010-09-21 17:00:17] philip@php.net Where do you see this? ------------------------------------------------------------------------ [2010-09-21 16:57:01] johnston dot joshua at gmail dot com Description: ------------ Please remove the cruft about using addslashes to escape data for database queries. It gives people the wrong idea. I know it says use mysql_real_escape string right after it, but even the suggestion of using addslashes gives new people the wrong idea. Tell them it's great for escaping strings for use in javascript or something. please! ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/bug.php?id=52901&edit=1

« previous php.doc.bugs (#5108) next »