note 43364 added to function.mysql-query

From: Date: Fri, 18 Jun 2004 22:22:35 +0000
Subject: note 43364 added to function.mysql-query
Groups: php.notes 
Request: Send a blank email to php-notes+get-71300@lists.php.net to get a copy of this message
If you want to check whether you can use mysql_fetch_* functions, do a compare against a bool value. Example below. Note the use of the !== operator instead of !=. <? $tmp = mysql_query($SQL); if(!$tmp) $error = true; else { $error = false; // no error if($tmp !== TRUE) $fields = mysql_fetch_assoc($tmp); else $fields = NULL; // no fields returned } ?> Edit to suit your needs. PS: Please ALWAYS remember to escape the parameters! I have taken as a rule to always form my SQL sentences like this: <? $SQL = 'select fields from table where key1='.sqlfix($a).' and key2='.sqlfix($b); ?> where sqlfix() is defined as follows: <? function sqlfix($s) { return "'".mysql_escape_string($s)."'"; } ?>This is very important for security, so I do not shame repeating the same thing said by others. ---- Manual Page -- http://www.php.net/manual/en/function.mysql-query.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+43364 Delete -- http://master.php.net/manage/user-notes.php?action=delete+43364&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+43364&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#71300) next »