Re: Session variables does not get sent
| From: | Chris Shiflett | Date: | Mon, 06 Sep 2004 07:12:38 +0000 |
| Subject: | Re: Session variables does not get sent | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-195961@lists.php.net to get a copy of this message | ||
--- Jason Wong <php-general@gremlins.biz> wrote:
> > $username = trim(addslashes($_POST['user_name']));
> > $pass = trim(addslashes($_POST['password']));
>
> addslashes() is not needed as you're performing SELECT query
> and not an INSERT query.
That's not true, since he's using user data in the SQL statement. The
query method has nothing to do with whether data should be escaped.
Of course, addslashes() is sort of a last result with regard to escaping
data for use in a query. The more preferable options are those native to
the database you're using, if they exist. MySQL users can use
mysql_escape_string(), for example.
Chris
=====
Chris Shiflett - http://shiflett.org/
PHP Security - O'Reilly
Coming Fall 2004
HTTP Developer's Handbook - Sams
http://httphandbook.org/
PHP Community Site
http://phpcommunity.org/