RE: [PHP] yet another quotation problem (kinda general)
| From: | Lawrence dot Sheed at dfait-maeci dot gc dot ca | Date: | Thu, 30 Nov 2000 03:19:37 +0000 |
| Subject: | RE: [PHP] yet another quotation problem (kinda general) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-27964@lists.php.net to get a copy of this message | ||
You could do a
stripslashes ($string);
addslashes ($string);
Which would ensure its escaped properly.
Otherwise configure php with magic_quotes set to off as a possibility in
your php settings.
Just some thoughts...
-----Original Message-----
From: Giovanni Tummarello [mailto:tummarel@ascu.unian.it]
Sent: November 30, 2000 11:18 AM
To: php-general@lists.php.net
Subject: [PHP] yet another quotation problem (kinda general)
Hi all..
as almost any1 in here i happen to have variables to be inserted intoa DB
(postgres in this case) and need proper escaping if i want the whole thing
not
to break down if a ' character comes in..
this is usually automatically done by php4 if a variable is posted from a
FORM.
.. but i have a function (logging function) that needs to work property with
both preescaped and non escaped variables.
How to do this? by recognizing wether a variable has been escaped already! I
have quickly come up with this thing here to check just this
here is the function
function StrtoDBStr($string) {
if (!ereg("[^\\\\]'",$string)) {
echo "YES";
} else
{echo "NO!";};
};
.. but it is of course not well functioning since it will not handle the
case
where a \ has been already escaped before .. IE this will return true
(since,
according to the regex, there are no ' that dont have a \ infront) while it
is
clearly not a valid "DB string":
it\\'s an example
Any1 can hack in a better regex to check for \\ \\\\ etc? (it appairs all
the
even number of \\ are to be considered not valid) or maybe some other
routine?
am i the only one with this problem ? :)
Thanks!
Sincerely
Giovanni Tummarello
tummarel@ascu.unian.it
Fight Spam! Join CAUCE (Coalition Against Unsolicited Commercial Email)
at http://www.cauce.org/ and tell your Congresspeople how
Spam
mailings
hurt you. Help protect genuine Internet commerce: Outlaw UCE
Spamming.
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net