Re: PHP and PostgreSQL
| From: | Michael Teter | Date: | Tue, 04 Jul 2000 18:56:28 +0000 |
| Subject: | Re: PHP and PostgreSQL | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-4796@lists.php.net to get a copy of this message | ||
You really shouldn't be trying to insert unvalidated
data into the database, for at least two reasons:
1. Your insert may fail.
2. Your insert may succeed, but you may end up with
trash data that's hard to find/remove.
It's extra work, but it's very important that you
validate each field before you attempt to insert it.
For example, say you have a form with Firstname,
Lastname, Zipcode, Comment.
You probably want to make sure that the user enters at
least a Lastname (make sure it's not empty spaces...
use a trim function.)
You want to make sure the Zipcode is just numeric
(assuming your database field type is numeric.)
You definitely want to make sure that no fields have
special characters, especially the ' character (single
quote.) Missing this will virtually guarantee your
insert will fail.
Then, if you really want to insert a NULL if the user
leaves a field blank (or has only spaces in it), you
can do that before you build your insert query.
michael
--- Teodor Cimpoesu <teo@digiro.net> wrote:
> Hi Corey!
> On Tue, 04 Jul 2000, Corey Mosher wrote:
>
> > Hi,
> > I am trying to do an insert into my postgreSQL
> database
> > from a form. When I try to insert a null value,
> it gets
> > put into the database as a string of spaces. Any
> ideas as to
> > why and how to insert the correct null value?
> >
> How do you know it's a string?
> did you run psql and select on the table, or you are
> talking about PHP
> values? If so, maybe PHP translated it into '' (null
> string) for you.
>
> -- teodor
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail:
> php-general-unsubscribe@lists.php.net
> For additional commands, e-mail:
> php-general-help@lists.php.net
> To contact the list administrators, e-mail:
> php-list-admin@lists.php.net
>
__________________________________________________
Do You Yahoo!?
Kick off your party with Yahoo! Invites.
http://invites.yahoo.com/