Addslashes still recommended for DB input
| From: | Stut | Date: | Tue, 21 Aug 2007 15:26:21 +0000 |
| Subject: | Addslashes still recommended for DB input | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-31791@lists.php.net to get a copy of this message | ||
The current php.ini-recommended in CVS for 5.2 has this at line 95...
; - magic_quotes_gpc = Off [Performance] ; Input data is no longer escaped with slashes so that it can be sent into ; SQL databases without further manipulation. Instead, you should use the ; function addslashes() on each input element you wish to send to a database.As far as I was aware addslashes is inadequate for this purpose. Should this not point people to use database-specific escaping functions rather than addslashes? -Stut -- http://stut.net/