note 31054 added to function.mysql-escape-string
| From: | Morat at rack1 dot php dot net | Date: | Tue, 08 Apr 2003 13:41:28 +0000 |
| Subject: | note 31054 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-46350@lists.php.net to get a copy of this message | ||
My approach to the slashes issue is to have a function which is called at the beginning of ever page
which checks whether magic_quotes_gpc is enabled and if so calls stripslashes on all the contents of
$_GET, $_POST and $_COOKIE. It also calls htmlspecialchars for each value, but this might not be to
everyone's taste.
I then do all my database access through a class that encapsulates connecting to and querying the
database, so my db access code is centralised. The Db->query($queryString, $database) function of
that class always calls mysql_escape_string on the query just before it sends it to the database.
With this approach I always know that data I use in my code is unescaped, but will be properly
escaped before being sent to mysql.
--
http://www.php.net/manual/en/function.mysql-escape-string.php
http://master.php.net/manage/user-notes.php?action=edit+31054
http://master.php.net/manage/user-notes.php?action=delete+31054
http://master.php.net/manage/user-notes.php?action=reject+31054