note 30879 added to function.mysql-escape-string

From: Date: Tue, 01 Apr 2003 22:48:42 +0000
Subject: note 30879 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-46103@lists.php.net to get a copy of this message
keep in mind that if the magic_quotes_xxx option is set to true, then all values containing single-quotes in a GET/POST/COOKIE query-string from a posting form will be automatically escaped before the engine page even loads. thus if you use this function on already escaped values, you will most likely end up with escape characters in the database entry as literals - rendering searches for that entry useless unless you escape the escaped characters in the search query! not very elegant... -- http://www.php.net/manual/en/function.mysql-escape-string.php http://master.php.net/manage/user-notes.php?action=edit+30879 http://master.php.net/manage/user-notes.php?action=delete+30879 http://master.php.net/manage/user-notes.php?action=reject+30879

« previous php.notes (#46103) next »