Doc #52901 [Opn->Wfx]: addslashes for database queries
| From: | aharvey@php.net | Date: | Wed, 22 Sep 2010 07:58:58 +0000 |
| Subject: | Doc #52901 [Opn->Wfx]: addslashes for database queries | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-5108@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=52901&edit=1
ID: 52901
Updated by: aharvey@php.net
Reported by: johnston dot joshua at gmail dot com
Summary: addslashes for database queries
-Status: Open
+Status: Wont fix
Type: Documentation Problem
Package: Documentation problem
Operating System: ALL
PHP Version: Irrelevant
Block user comment: N
New Comment:
I'd say the text there is already correct: it says to use the DBMS
specific escaping function if there is one, but there are database
extensions without escaping functions, in which case addslashes() is the
correct function to use.
Previous Comments:
------------------------------------------------------------------------
[2010-09-21 17:10:33] johnston dot joshua at gmail dot com
http://php.net/addslashes
Under Desc the first two sentences are:
Returns a string with backslashes before characters that need to be
quoted in database queries etc. These characters are single quote ('),
double quote ("), backslash (\) and NUL (the NULL byte).
An example use of addslashes() is when you're entering data into a
database. For example, to insert the name O'reilly into a database, you
will need to escape it.
------------------------------------------------------------------------
[2010-09-21 17:00:17] philip@php.net
Where do you see this?
------------------------------------------------------------------------
[2010-09-21 16:57:01] johnston dot joshua at gmail dot com
Description:
------------
Please remove the cruft about using addslashes to escape data for
database queries. It gives people the wrong idea.
I know it says use mysql_real_escape string right after it, but even the
suggestion of using addslashes gives new people the wrong idea. Tell
them it's great for escaping strings for use in javascript or something.
please!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=52901&edit=1