note 30879 added to function.mysql-escape-string
| From: | wmethlie at anotherreason dot com | Date: | Tue, 01 Apr 2003 22:48:42 +0000 |
| Subject: | note 30879 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-46103@lists.php.net to get a copy of this message | ||
keep in mind that if the magic_quotes_xxx option is set to true, then all values containing
single-quotes in a GET/POST/COOKIE query-string from a posting form will be automatically escaped
before the engine page even loads.
thus if you use this function on already escaped values, you will most likely end up with escape
characters in the database entry as literals - rendering searches for that entry useless unless you
escape the escaped characters in the search query! not very elegant...
--
http://www.php.net/manual/en/function.mysql-escape-string.php
http://master.php.net/manage/user-notes.php?action=edit+30879
http://master.php.net/manage/user-notes.php?action=delete+30879
http://master.php.net/manage/user-notes.php?action=reject+30879