note 41720 added to function.mysql-query

From: Date: Tue, 20 Apr 2004 23:59:17 +0000
Subject: note 41720 added to function.mysql-query
Groups: php.notes 
Request: Send a blank email to php-notes+get-68394@lists.php.net to get a copy of this message
Here is better placeholder replacement function. Use mysql_qw("SELECT * FROM t WHERE name=?", $name) instead of mysql_query("SELECT * FROM t WHERE name='$name'") - it is much more secure. Why PHP developers have not included this (or similar) function in PHP core? Mystery. <?php // result-set mysql_qw($connection_id, $query, $arg1, $arg2, ...) // - or - // result-set mysql_qw($query, $arg1, $arg2, ...) function mysql_qw() { $args = func_get_args(); $conn = null; if (is_resource($args[0])) $conn = array_shift($args); $query = call_user_func_array("mysql_make_qw", $args); return $conn!==null? mysql_query($query, $conn) : mysql_query($query); } // string mysql_make_qw($query, $arg1, $arg2, ...) function mysql_make_qw() { $args = func_get_args(); $tmpl =& $args[0]; $tmpl = str_replace("%", "%%", $tmpl); $tmpl = str_replace("?", "%s", $tmpl); foreach ($args as $i=>$v) { if (!$i) continue; if (is_int($v)) continue; $args[$i] = "'".mysql_escape_string($v)."'"; } for ($i=$c=count($args)-1; $i<$c+20; $i++) $args[$i+1] = "UNKNOWN_PLACEHOLDER_$i"; return call_user_func_array("sprintf", $args); } ?> ---- Manual Page -- http://www.php.net/manual/en/function.mysql-query.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+41720 Delete -- http://master.php.net/manage/user-notes.php?action=delete+41720&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+41720&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#68394) next »