note 31638 deleted from function.stripslashes by irchtml
| From: | irchtml@php.net | Date: | Wed, 25 Feb 2004 20:48:06 +0000 |
| Subject: | note 31638 deleted from function.stripslashes by irchtml | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-65761@lists.php.net to get a copy of this message | ||
Note Submitter: kurnia@del.ac.id
----
You will need stripslashes() when you are taking a query as a form variable (i.e.
$_POST($your_query)).
example:
You define an input variable named your_query, and you want to pass it thru when you press submit
button in the form.
Your proses_query.php will consist:
//first, you take your input into a variable
$my_command = $_POST[your_query];
/* you have to stripslashes the content of variable, to leave out all the slashes that has been put
by PHP when you pass it thru via submit button*/
$my_command=stripslashes($my_command);
$do_the_query=mysql_query($my_command);
NOTE: be sure to do stripslashes when you query consist of stripslases such as insert, etc.
However you may not need it when your query only select * from your_table_name (notice no slashes in
it).
However for best practice, it's good for you to generalize it by using stripslashes, otherwise
you'll get an error message.