note 63444 deleted from function.mysql-real-escape-string by bjori

From: Date: Wed, 22 Mar 2006 17:45:53 +0000
Subject: note 63444 deleted from function.mysql-real-escape-string by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-106275@lists.php.net to get a copy of this message
Note Submitter: webograph at eml dot cc Reason: in docs ---- using printf %d / '%s' in connection with possibly numeric values can save you from trouble: <?php mysql_query(sprintf("SELECT foo FROM bar WHERE some_string='%s' AND a_number=%d",mysql_real_escape_string($string),$number)); ?> if you long for simple execution of queries, you can use a function like this as a wrapper for mysql_query (roughly emulates the way of python): <?php function mq($query, $args=NULL) { // calling without a second argument should not make printf fail if($args!==NULL && !is_array($args)) $args=array($args); if($args) foreach($args as $i => $v) $args[$i]=mysql_real_escape_string($v); $q=vsprintf($query,$args) // logging could go here $q=mysql_query($q); // error handling could go here return $q; } $query=mq("SELECT * FROM foo WHERE bar='%s'",$string); ... $query=mq("SELECT * FROM foo WHERE bar='%s' AND baz=%d",array($string,$number)); ?> such a function can also contain script-wide error handling instead of widespread mysql_query(...) or die("Error in line ".__LINE__");

« previous php.notes (#106275) next »