note 34234 deleted from function.mysql-escape-string by nicos
| From: | nicos@php.net | Date: | Fri, 25 Jul 2003 09:43:18 +0000 |
| Subject: | note 34234 deleted from function.mysql-escape-string by nicos | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-52628@lists.php.net to get a copy of this message | ||
Note Submitter: daniel141@yahoo.com
----
Here are a few functions that you may like... They should solve a lot of issues.
This first function will properly format your string for mysql database use... Common misteak would
be to stripslashes but then a string like "Go to C:\Windows\" would output "Go to
C:windows" This will solve that problem.
function escape($string)
{
$string = str_replace(array('\\"', "\\'", '\\\\'),
array('"', "'", '\\'), $string);
return mysql_escape_string($string);
}
You can't turn magic_quotes_gpc on or off during runtime, but you can use this function to
simulate turning it on and off
set_magic_quotes(0); would simulate it being switched off
set_magic_quotes(1); would simulate it being switched on
function set_magic_quotes($status = 0)
{
global $magic_quote_status;
if(!isset($magic_quote_status))
{
$magic_quote_status = get_magic_quotes_gpc();
}
// We only want to run this if it needs to be changed
if($magic_quote_status != $status)
{
// Do we want to turn it on, or off?
if($status)
{
// Turn it on
foreach($_GET as $var => $val)
{
$_GET[$var] = mysql_escape_string($val);
}
foreach($_POST as $var => $val)
{
$_POST[$var] = mysql_escape_string($val);
}
foreach($_COOKIE as $var => $val)
{
$_COOKIE[$var] = mysql_escape_string($val);
}
}
else
{
// Turn it off
foreach($_GET as $var => $val)
{
$_GET[$var] = str_replace(array('\\"', "\\'",
'\\\\'), array('"', "'", '\\'), $val);
}
foreach($_POST as $var => $val)
{
$_POST[$var] = str_replace(array('\\"', "\\'",
'\\\\'), array('"', "'", '\\'), $val);
}
foreach($_COOKIE as $var => $val)
{
$_COOKIE[$var] = str_replace(array('\\"', "\\'",
'\\\\'), array('"', "'", '\\'), $val);
}
}
}
$magic_quote_status = $status;
}
Good luck!