note 71697 deleted from function.mysql-real-escape-string by nlopess
| From: | nlopess@php.net | Date: | Sun, 31 Dec 2006 12:23:35 +0000 |
| Subject: | note 71697 deleted from function.mysql-real-escape-string by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-121138@lists.php.net to get a copy of this message | ||
Note Submitter: Nobody
----
@federico at nextware dot it
I think you misunderstand the function of escaping:
If you use $var = "line1\nline2" then \n is stored as 1 char in $var, so that echo $var
will print 2 lines of text.
If you use $var2 = "line1\nline2" then \n is not interpreted and stored as it is with 2
chars of size.
The main difference is, that if you youse '...' syntax, then there is no way to place a
literal ' char inside:
e.g. 'she\'s' produces an error.
On the other hand, when you use "..." syntax, then you can anyway use the literal "
inside:
e.g. $var3 = "She say\"Go away!\""; echo $var3 will print
She say "Go away!" .
So come back to your example:
Given: '\"text\"'
Two assertions possible, with neither of one will match your result:
a) $your_var = "'\"text\"'";//sourrounding the given with
""
mysql_real_escape_string($your_var) === '\'\"text\"\'' ===true
b) $your_var = '\"text\"'; //assert without adding anything to the given
mysql_real_escape_string($your_var) === '\\\"text\\\"' ===true
c) $your_var = ''\"text\"'';//sourrounding with ''. -->
Error in Parsing!
Cu.