note 41720 added to function.mysql-query
| From: | d at koteroff dot ru | Date: | Tue, 20 Apr 2004 23:59:17 +0000 |
| Subject: | note 41720 added to function.mysql-query | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-68394@lists.php.net to get a copy of this message | ||
Here is better placeholder replacement function. Use
mysql_qw("SELECT * FROM t WHERE name=?", $name)
instead of
mysql_query("SELECT * FROM t WHERE name='$name'")
- it is much more secure. Why PHP developers have not included this (or similar) function in PHP
core? Mystery.
<?php
// result-set mysql_qw($connection_id, $query, $arg1, $arg2, ...)
// - or -
// result-set mysql_qw($query, $arg1, $arg2, ...)
function mysql_qw() {
$args = func_get_args();
$conn = null;
if (is_resource($args[0])) $conn = array_shift($args);
$query = call_user_func_array("mysql_make_qw", $args);
return $conn!==null? mysql_query($query, $conn) : mysql_query($query);
}
// string mysql_make_qw($query, $arg1, $arg2, ...)
function mysql_make_qw() {
$args = func_get_args();
$tmpl =& $args[0];
$tmpl = str_replace("%", "%%", $tmpl);
$tmpl = str_replace("?", "%s", $tmpl);
foreach ($args as $i=>$v) {
if (!$i) continue;
if (is_int($v)) continue;
$args[$i] = "'".mysql_escape_string($v)."'";
}
for ($i=$c=count($args)-1; $i<$c+20; $i++)
$args[$i+1] = "UNKNOWN_PLACEHOLDER_$i";
return call_user_func_array("sprintf", $args);
}
?>
----
Manual Page -- http://www.php.net/manual/en/function.mysql-query.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+41720
Delete -- http://master.php.net/manage/user-notes.php?action=delete+41720&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+41720&report=yes
Search -- http://master.php.net/manage/user-notes.php