note 59895 added to function.vsprintf
| From: | toneeeatgmaildotcom at osu1 dot php dot net | Date: | Mon, 19 Dec 2005 17:27:45 +0000 |
| Subject: | note 59895 added to function.vsprintf | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-100418@lists.php.net to get a copy of this message | ||
I found this function to be useful for formatting sql queries.
I do something like this:
function sql_build($template, $params = array()) {
global $sql_templates;
if (isset($sql_templates[$template])) {
$sql = vsprintf($sql_templates[$template], $params);
return $sql;
}
return false;
}
// Fetch list of contacts, for a given section id
$sql_templates['contacts_by_section'] = <<<ENDSQL
select
id,
name,
email,
address,
photo_id
from
contacts
where
section_id = %d
ENDSQL;
You also give yourself an added layer of security on the sql due to the sprintf formatting. For
example, using %d will not allow any sql injection for that parameter.
----
Manual Page -- http://www.php.net/manual/en/function.vsprintf.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+59895
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59895&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59895&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59895&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59895&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59895&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59895&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59895&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+59895&report=yes
Search -- http://master.php.net/manage/user-notes.php