note 30844 deleted from function.mysql-escape-string by aidan
| From: | aidan@php.net | Date: | Wed, 11 Aug 2004 14:07:53 +0000 |
| Subject: | note 30844 deleted from function.mysql-escape-string by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-74449@lists.php.net to get a copy of this message | ||
Note Submitter: p2pwrox@ndc.co.za
----
Have any of you bothered to read the MySQL manual?
mysql_escape_string() is used to "create a legal SQL string that you can use in a SQL
statement". It's primary use is to allow binary BLOB data to co-exist within an ASCII SQL
statement without confusing the SQL parser. For this reason tokens such as " and ' are
escaped so the parser doesn't think you're ending the blob string prematurely. NUL is
escaped because mysql is written in C and uses C strings which use NUL as a terminator. Similar
explanations apply for the other escaped chars.
Protecting an SQL string from abuse is NOT the primary reason for this function. It's just a
bonus!