note 35526 deleted from function.mysql-escape-string by didou
| From: | didou@php.net | Date: | Tue, 27 Jan 2004 08:36:52 +0000 |
| Subject: | note 35526 deleted from function.mysql-escape-string by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-64232@lists.php.net to get a copy of this message | ||
Note Submitter: homer400@yahoo.NOSPAM.com
----
Make a class that encapsulates all db access that includes string escaping. Currently I am using
this type of approach:
<?
$query = GetDataQuery("INSERT INTO #articles (CategoryID, UserID, CreatedOn, UpdatedOn, Title,
Description, ArticleText) VALUES (?,?,NOW(),NOW(),?,?,?)");
$query->setParams($CategoryID, $UserID, $Article[Title], $Article[Description],
$ArticleArray[UnparsedArticle]);
$query->Execute();
?>
The great thing about it is that I can change my table prefix very easily, all my parameters are
escaped, the class doesn't rely on Default connections handles, and mysql_select_db is used on
every call. If you are worried about doubled slashes saved in your db, you can call
mysql_real_escape_string(stripslashes($string), $this->linkDatabase) in your execute.