note 30879 deleted from function.mysql-escape-string by aidan
| From: | aidan@php.net | Date: | Wed, 11 Aug 2004 14:07:48 +0000 |
| Subject: | note 30879 deleted from function.mysql-escape-string by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-74448@lists.php.net to get a copy of this message | ||
Note Submitter: wmethlie@anotherreason.com
----
keep in mind that if the magic_quotes_xxx option is set to true, then all values containing
single-quotes in a GET/POST/COOKIE query-string from a posting form will be automatically escaped
before the engine page even loads.
thus if you use this function on already escaped values, you will most likely end up with escape
characters in the database entry as literals - rendering searches for that entry useless unless you
escape the escaped characters in the search query! not very elegant...