Re: Re: Difference between $_POST[foo] and $_POST['foo']?
| From: | Adam Voigt | Date: | Tue, 17 Jun 2003 15:00:38 +0000 |
| Subject: | Re: Re: Difference between $_POST[foo] and $_POST['foo']? | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-151841@lists.php.net to get a copy of this message | ||
Actually I didn't.
The code that I gave would result in a string like:
select * from db where apple = 'blah';
For your reference:
\'' means print one single quote then end the current stream.
Then the . $_POST['foo'] appends the value of foo to the stream,
then . '\';'; prints one more single quote to end the quote's around
the value, and adds a semicolon at the end of the string to tell
MySQL the query has ended.
On Tue, 2003-06-17 at 10:36, Chris Hayes wrote:
> At 16:19 17-6-03, you wrote:
> >$sql = 'select * from db where apple = \'' . $_POST['foo'] .
> >'\';';
> >Like that?
> you missed some quotes:
> $sql = 'select * from db where apple = \''' . $_POST['foo'] .
> '\'"';
>
--
Adam Voigt (adam@cryptocomm.com)
Linux/Unix Network Administrator
The Cryptocomm Group