Re: regex and mysql - looking for opinions.
| From: | Plutarck | Date: | Wed, 18 Apr 2001 21:55:55 +0000 |
| Subject: | Re: regex and mysql - looking for opinions. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-49281@lists.php.net to get a copy of this message | ||
I use a special function just for reforming input, but they use the
following bits with PCRE:
$replace_wordwhite = '/[^\w\s]/';
$replace_word = '/\W/';
$replace_num = '/\D/';
$replace_email = '/[^\w\-\.@]/';
Works pretty well and it's quite useful for killing useless input without
returning errors, so the username (for instance) "B{o}b" it made into "Bob".
That way it's more or less forgiving of morons and malicious users alike :)
--
Plutarck
Should be working on something...
...but forgot what it was.
"Larry Hotchkiss" <no.spam.lhotch@unicap.com> wrote in message
news:3ADDF310.F15B025B@unicap.com...
> Im working on a site utilizing apaches/mysqp and of course php. Im
> working through the basic framwork creating forms to collect user input
> and do various searches etc. I was curious as to what most people find
> the best way keep thier mysql queries from getting messed up by user
> entered data. None of my searches or database data has or needs any sort
> of punctuation, so I was thinking of striping it all out from form
> input. What method is everyone else using?
>
>
> --
> Larry H.
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>