note 43364 deleted from function.mysql-query by philip

From: Date: Wed, 06 Apr 2005 18:01:27 +0000
Subject: note 43364 deleted from function.mysql-query by philip
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-87601@lists.php.net to get a copy of this message
Note Submitter: bisqwit at iki dot fi ---- If you want to check whether you can use mysql_fetch_* functions, do a compare against a bool value. Example below. Note the use of the !== operator instead of !=. <? $tmp = mysql_query($SQL); if(!$tmp) $error = true; else { $error = false; // no error if($tmp !== TRUE) $fields = mysql_fetch_assoc($tmp); else $fields = NULL; // no fields returned } ?> Edit to suit your needs. PS: Please ALWAYS remember to escape the parameters! I have taken as a rule to always form my SQL sentences like this: <? $SQL = 'select fields from table where key1='.sqlfix($a).' and key2='.sqlfix($b); ?> where sqlfix() is defined as follows: <? function sqlfix($s) { return "'".mysql_escape_string($s)."'"; } ?>This is very important for security, so I do not shame repeating the same thing said by others.

« previous php.notes (#87601) next »