note 43364 deleted from function.mysql-query by philip
| From: | philip@php.net | Date: | Wed, 06 Apr 2005 18:01:27 +0000 |
| Subject: | note 43364 deleted from function.mysql-query by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-87601@lists.php.net to get a copy of this message | ||
Note Submitter: bisqwit at iki dot fi
----
If you want to check whether you can use mysql_fetch_* functions, do a compare against a bool value.
Example below. Note the use of the !== operator instead of !=.
<?
$tmp = mysql_query($SQL);
if(!$tmp)
$error = true;
else
{
$error = false; // no error
if($tmp !== TRUE)
$fields = mysql_fetch_assoc($tmp);
else
$fields = NULL; // no fields returned
}
?>
Edit to suit your needs.
PS: Please ALWAYS remember to escape the parameters! I have taken as a rule to always form my SQL
sentences like this:
<?
$SQL = 'select fields from table where key1='.sqlfix($a).' and
key2='.sqlfix($b);
?>
where sqlfix() is defined as follows:
<?
function sqlfix($s)
{
return "'".mysql_escape_string($s)."'";
}
?>This is very important for security, so I do not shame repeating the same thing said by others.