RE: [PHP] yet another quotation problem (kinda general)

From: Date: Thu, 30 Nov 2000 03:19:37 +0000
Subject: RE: [PHP] yet another quotation problem (kinda general)
Groups: php.general 
Request: Send a blank email to php-general+get-27964@lists.php.net to get a copy of this message
You could do a stripslashes ($string); addslashes ($string); Which would ensure its escaped properly. Otherwise configure php with magic_quotes set to off as a possibility in your php settings. Just some thoughts... -----Original Message----- From: Giovanni Tummarello [mailto:tummarel@ascu.unian.it] Sent: November 30, 2000 11:18 AM To: php-general@lists.php.net Subject: [PHP] yet another quotation problem (kinda general) Hi all.. as almost any1 in here i happen to have variables to be inserted intoa DB (postgres in this case) and need proper escaping if i want the whole thing not to break down if a ' character comes in.. this is usually automatically done by php4 if a variable is posted from a FORM. .. but i have a function (logging function) that needs to work property with both preescaped and non escaped variables. How to do this? by recognizing wether a variable has been escaped already! I have quickly come up with this thing here to check just this here is the function function StrtoDBStr($string) { if (!ereg("[^\\\\]'",$string)) { echo "YES"; } else {echo "NO!";}; }; .. but it is of course not well functioning since it will not handle the case where a \ has been already escaped before .. IE this will return true (since, according to the regex, there are no ' that dont have a \ infront) while it is clearly not a valid "DB string": it\\'s an example Any1 can hack in a better regex to check for \\ \\\\ etc? (it appairs all the even number of \\ are to be considered not valid) or maybe some other routine? am i the only one with this problem ? :) Thanks! Sincerely Giovanni Tummarello tummarel@ascu.unian.it Fight Spam! Join CAUCE (Coalition Against Unsolicited Commercial Email) at http://www.cauce.org/ and tell your Congresspeople how Spam mailings hurt you. Help protect genuine Internet commerce: Outlaw UCE Spamming. -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#27964) next »