note 30783 added to function.mysql-query

From: Date: Fri, 28 Mar 2003 11:35:21 +0000
Subject: note 30783 added to function.mysql-query
Groups: php.notes 
Request: Send a blank email to php-notes+get-45946@lists.php.net to get a copy of this message
One way to reduce the dangers of queries like the dlete command above that dletes the whole DB is to use limits wherever possible. EG. If you have a routine that is only deisnged to delete 1 record, add 'LIMIT 1' to the end of the command. This way you'll only lose one record if someone does something stupid. You should also check all input, especially if it is sent using GET. ie. make sure that $_GET['id'] is not NULL or == "", is a number that is positive, not 0 (generally, I know this doesn't apply to some table types, but it applies to the default) and is within the valid range for that field. Just don't trust ANY data that is sent to your script. HTH Allen -- http://www.php.net/manual/en/function.mysql-query.php http://master.php.net/manage/user-notes.php?action=edit+30783 http://master.php.net/manage/user-notes.php?action=delete+30783 http://master.php.net/manage/user-notes.php?action=reject+30783

« previous php.notes (#45946) next »