note 53767 added to function.mysql-real-escape-string
| From: | dotpointer at osu1 dot php dot net | Date: | Sun, 12 Jun 2005 17:13:53 +0000 |
| Subject: | note 53767 added to function.mysql-real-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-90307@lists.php.net to get a copy of this message | ||
--- Note 1 ---
"Strictly speaking, MySQL requires only that backslash and
the quote character used to quote the string in the query
be escaped. This function quotes the other characters to
make them easier to read in log files."
(Source: http://dev.mysql.com/doc/mysql/en/mysql-real-escape-string.html)
--- Note 2 ---
\x1a = CTRL+Z.
mysql_real_escape_string() translates \x1a to \Z.
Backslashes (92) are used, not \e (27). Same as with addslashes().
--- Note 4 ---
Running mysql_real_escape_string() on already
backslashed data will add unwanted backslashes.
If PHP setting magic quotes is ON, POST, GET, FILES are
auto-slashed. See note 6 howto detect.
--- Note 5 ---
IF the connection to MySQL FAILS and the real
mysql_real_escape_string-API can't be run, then PHP
seems to slash only \-chars and '-chars in an home-made
way. Here are comments from the PHP 5.0.4 sourcecode:
"/* mysql_real_escape_string failed, just do my own escaping then */
/* replace \ with \\ */"
/* ' with '' */"
(Source: php-5.0.4\ext\dbx\dbx_mysql.c (lines 276-294))
Quite scary?
--- Note 6 ---
"A 'Best Practice' query: [...]
function quote_smart($value)
{
// Stripslashes
if (get_magic_quotes_gpc()) {
$value = stripslashes($value);
}
// Quote if not integer
if (!is_numeric($value)) {
$value = "'" . mysql_real_escape_string($value) . "'";
}
return $value;
}
"
(Source: http://www.zend.com/manual/function.mysql-real-escape-string.php)
--- Note 7 ---
A function that only slashes unslashed data would be appreciated.
If I come up with something I will post a note.
----
Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+53767
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+53767&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+53767&report=yes
Search -- http://master.php.net/manage/user-notes.php