note 53767 added to function.mysql-real-escape-string

From: Date: Sun, 12 Jun 2005 17:13:53 +0000
Subject: note 53767 added to function.mysql-real-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-90307@lists.php.net to get a copy of this message
--- Note 1 --- "Strictly speaking, MySQL requires only that backslash and the quote character used to quote the string in the query be escaped. This function quotes the other characters to make them easier to read in log files." (Source: http://dev.mysql.com/doc/mysql/en/mysql-real-escape-string.html) --- Note 2 --- \x1a = CTRL+Z. mysql_real_escape_string() translates \x1a to \Z. Backslashes (92) are used, not \e (27). Same as with addslashes(). --- Note 4 --- Running mysql_real_escape_string() on already backslashed data will add unwanted backslashes. If PHP setting magic quotes is ON, POST, GET, FILES are auto-slashed. See note 6 howto detect. --- Note 5 --- IF the connection to MySQL FAILS and the real mysql_real_escape_string-API can't be run, then PHP seems to slash only \-chars and '-chars in an home-made way. Here are comments from the PHP 5.0.4 sourcecode: "/* mysql_real_escape_string failed, just do my own escaping then */ /* replace \ with \\ */" /* ' with '' */" (Source: php-5.0.4\ext\dbx\dbx_mysql.c (lines 276-294)) Quite scary? --- Note 6 --- "A 'Best Practice' query: [...] function quote_smart($value) { // Stripslashes if (get_magic_quotes_gpc()) { $value = stripslashes($value); } // Quote if not integer if (!is_numeric($value)) { $value = "'" . mysql_real_escape_string($value) . "'"; } return $value; } " (Source: http://www.zend.com/manual/function.mysql-real-escape-string.php) --- Note 7 --- A function that only slashes unslashed data would be appreciated. If I come up with something I will post a note. ---- Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+53767 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+53767&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#90307) next »