note 63444 deleted from function.mysql-real-escape-string by bjori
| From: | bjori@php.net | Date: | Wed, 22 Mar 2006 17:45:53 +0000 |
| Subject: | note 63444 deleted from function.mysql-real-escape-string by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-106275@lists.php.net to get a copy of this message | ||
Note Submitter: webograph at eml dot cc
Reason: in docs
----
using printf %d / '%s' in connection with possibly numeric values can save you from
trouble:
<?php
mysql_query(sprintf("SELECT foo FROM bar WHERE some_string='%s' AND
a_number=%d",mysql_real_escape_string($string),$number));
?>
if you long for simple execution of queries, you can use a function like this as a wrapper for
mysql_query (roughly emulates the way of python):
<?php
function mq($query, $args=NULL)
{
// calling without a second argument should not make printf fail
if($args!==NULL && !is_array($args)) $args=array($args);
if($args) foreach($args as $i => $v) $args[$i]=mysql_real_escape_string($v);
$q=vsprintf($query,$args)
// logging could go here
$q=mysql_query($q);
// error handling could go here
return $q;
}
$query=mq("SELECT * FROM foo WHERE bar='%s'",$string);
...
$query=mq("SELECT * FROM foo WHERE bar='%s' AND baz=%d",array($string,$number));
?>
such a function can also contain script-wide error handling instead of widespread mysql_query(...)
or die("Error in line ".__LINE__");