Re: [RFC] New function mysqli_quote_string
| From: | Matteo Beccati | Date: | Fri, 19 Dec 2025 13:52:17 +0000 |
| Subject: | Re: [RFC] New function mysqli_quote_string | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-129657@lists.php.net to get a copy of this message | ||
Hi Kamil,
Il 18/12/2025 22:03, Kamil Tekiela ha scritto:
Hello, I would like to open a discussion about adding a new function to PHP https://wiki.php.net/rfc/mysqli_quote_string Would you support such an addition?I agree with you and I prefer PDO::quote()'s behaviour over the "old" non-pdo quote functions. However, I also think that manually interpolating parameters is not a best practice that we should encourage: query parameters are the a much better defence against SQL injections. Also I'm afraid that offering two alternatives would increase the confusion, especially if this new function is added only to mysqli and not other prominent database extensions. Cheers -- Matteo