note 34234 added to function.mysql-escape-string
| From: | daniel141 at yahoo dot com | Date: | Sat, 19 Jul 2003 04:19:48 +0000 |
| Subject: | note 34234 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-52371@lists.php.net to get a copy of this message | ||
Here are a few functions that you may like... They should solve a lot of issues.
This first function will properly format your string for mysql database use... Common misteak would
be to stripslashes but then a string like "Go to C:\Windows\" would output "Go to
C:windows" This will solve that problem.
function escape($string)
{
$string = str_replace(array('\\"', "\\'", '\\\\'),
array('"', "'", '\\'), $string);
return mysql_escape_string($string);
}
You can't turn magic_quotes_gpc on or off during runtime, but you can use this function to
simulate turning it on and off
set_magic_quotes(0); would simulate it being switched off
set_magic_quotes(1); would simulate it being switched on
function set_magic_quotes($status = 0)
{
global $magic_quote_status;
if(!isset($magic_quote_status))
{
$magic_quote_status = get_magic_quotes_gpc();
}
// We only want to run this if it needs to be changed
if($magic_quote_status != $status)
{
// Do we want to turn it on, or off?
if($status)
{
// Turn it on
foreach($_GET as $var => $val)
{
$_GET[$var] = mysql_escape_string($val);
}
foreach($_POST as $var => $val)
{
$_POST[$var] = mysql_escape_string($val);
}
foreach($_COOKIE as $var => $val)
{
$_COOKIE[$var] = mysql_escape_string($val);
}
}
else
{
// Turn it off
foreach($_GET as $var => $val)
{
$_GET[$var] = str_replace(array('\\"', "\\'",
'\\\\'), array('"', "'", '\\'), $val);
}
foreach($_POST as $var => $val)
{
$_POST[$var] = str_replace(array('\\"', "\\'",
'\\\\'), array('"', "'", '\\'), $val);
}
foreach($_COOKIE as $var => $val)
{
$_COOKIE[$var] = str_replace(array('\\"', "\\'",
'\\\\'), array('"', "'", '\\'), $val);
}
}
}
$magic_quote_status = $status;
}
Good luck!
----
Manual Page -- http://www.php.net/manual/en/function.mysql-escape-string.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+34234
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+34234&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+34234&report=yes