note 43364 added to function.mysql-query
| From: | bisqwit at iki dot fi | Date: | Fri, 18 Jun 2004 22:22:35 +0000 |
| Subject: | note 43364 added to function.mysql-query | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-71300@lists.php.net to get a copy of this message | ||
If you want to check whether you can use mysql_fetch_* functions, do a compare against a bool value.
Example below. Note the use of the !== operator instead of !=.
<?
$tmp = mysql_query($SQL);
if(!$tmp)
$error = true;
else
{
$error = false; // no error
if($tmp !== TRUE)
$fields = mysql_fetch_assoc($tmp);
else
$fields = NULL; // no fields returned
}
?>
Edit to suit your needs.
PS: Please ALWAYS remember to escape the parameters! I have taken as a rule to always form my SQL
sentences like this:
<?
$SQL = 'select fields from table where key1='.sqlfix($a).' and
key2='.sqlfix($b);
?>
where sqlfix() is defined as follows:
<?
function sqlfix($s)
{
return "'".mysql_escape_string($s)."'";
}
?>This is very important for security, so I do not shame repeating the same thing said by others.
----
Manual Page -- http://www.php.net/manual/en/function.mysql-query.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+43364
Delete -- http://master.php.net/manage/user-notes.php?action=delete+43364&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+43364&report=yes
Search -- http://master.php.net/manage/user-notes.php