note 31054 added to function.mysql-escape-string

From: Date: Tue, 08 Apr 2003 13:41:28 +0000
Subject: note 31054 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-46350@lists.php.net to get a copy of this message
My approach to the slashes issue is to have a function which is called at the beginning of ever page which checks whether magic_quotes_gpc is enabled and if so calls stripslashes on all the contents of $_GET, $_POST and $_COOKIE. It also calls htmlspecialchars for each value, but this might not be to everyone's taste. I then do all my database access through a class that encapsulates connecting to and querying the database, so my db access code is centralised. The Db->query($queryString, $database) function of that class always calls mysql_escape_string on the query just before it sends it to the database. With this approach I always know that data I use in my code is unescaped, but will be properly escaped before being sent to mysql. -- http://www.php.net/manual/en/function.mysql-escape-string.php http://master.php.net/manage/user-notes.php?action=edit+31054 http://master.php.net/manage/user-notes.php?action=delete+31054 http://master.php.net/manage/user-notes.php?action=reject+31054

« previous php.notes (#46350) next »