Re: mysql escape character \'

From: Date: Tue, 07 Aug 2001 15:49:44 +0000
Subject: Re: mysql escape character \'
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-61647@lists.php.net to get a copy of this message
----- Original Message ----- From: hassan el forkani <webmaster@warmafrica.com> Sent: Tuesday, August 07, 2001 07:32 > greetings; > > i'm not sure if this is a mysql or php issue so i'm posting to both lists, > > i'm developping a community web site with news, forums......; > while working on the admin section i noticed this behaviour: > > on my hosting platform (linux) > i need to replace single quotes by \' to properly insert the data into the > database and avoid errors > on my dev machine (win98) there is no need to do so as single quotes are > properly inserted and attempting to escape them actually inserts \' instead > of '; > > so the same code does not have the same output on windows and linux > > can someone explain?? > Well, what I use for any form fields that may have special characters in them (text, textarea) is a combination of htmlspecialchars() and addslashes() on input, and stripslashes() on output - for example: $textfield = "some&strange'text"; $escaped = addslashes(htmlspecialchars($textfield)); $sql = "INSERT INTO table VALUES (textfield), ('$escaped')"; ... db query ...; now, the special characters such as ampersand are converted into their hex equivalents, and any characters that need to be escaped are escaped properly... All you need to do now is remember to use stripslashes() on output: $sql = "SELECT textfield FROM table WHERE id = '1'"; ... db query ...; echo stripslashes($textfield); for more info see the appropriate manual pages: http://www.php.net/manual/en/function.htmlspecialchars.php http://www.php.net/manual/en/function.addslashes.php http://www.php.net/manual/en/function.stripslashes.php Hope this helps Anton Stroganov www.artwithin.com webmaster

« previous php.general (#61647) next »