note 21598 deleted from function.mysql-query by cece
| From: | cece@php.net | Date: | Sun, 14 Nov 2004 13:24:21 +0000 |
| Subject: | note 21598 deleted from function.mysql-query by cece | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-80500@lists.php.net to get a copy of this message | ||
Note Submitter: frank at boumphrey dot com
----
Here is a danger that I accidently came across. I hope knowledge of it it will save others from the
grief it caused me!
Consider the following SQL statement expressed as a PHP statement:
$strSQL="DELETE FROM clients WHERE client_id=".client_id;
What I mean to put of course was:
$strSQL="DELETE FROM clients WHERE client_id=".$client_id;
However the first statement is expanded by PHP to:
"DELETE FROM clients WHERE client_id=client_id"
AND RUNNING THIS SQL QUERY WILL DELETE THE _WHOLE_ OF YOUR TABLE CONTENT!!!
It is the equivalent of:
"DELETE FROM clients;"
This can really spoil your day!
Frank