note 37765 added to function.addslashes

From: Date: Tue, 25 Nov 2003 22:28:52 +0000
Subject: note 37765 added to function.addslashes
Groups: php.notes 
Request: Send a blank email to php-notes+get-60987@lists.php.net to get a copy of this message
Running apache/php under win2k, with magic_quotes_gpc on, querying MS Sql-server via ODBC, I needed to escape single quotes (e.g. O'Neal). addslashes() was not the solution. Instead, I wrote the following function, which uses a single quote to escape the single quote, as per the ansi standard sql: function sani($txt){ if(stristr($txt, "'")){ $txt=ereg_replace("'","''", $txt); return stripslashes($txt); } } then I enter queries like: "select column from table where column like '".sani($find)."%'" ---- Manual Page -- http://www.php.net/manual/en/function.addslashes.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+37765 Delete -- http://master.php.net/manage/user-notes.php?action=delete+37765&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+37765&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#60987) next »