note 53767 deleted from function.mysql-real-escape-string by nlopess
| From: | nlopess@php.net | Date: | Fri, 29 Jul 2005 10:36:33 +0000 |
| Subject: | note 53767 deleted from function.mysql-real-escape-string by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-92721@lists.php.net to get a copy of this message | ||
Note Submitter: dotpointer
----
--- Note 1 ---
"Strictly speaking, MySQL requires only that backslash and
the quote character used to quote the string in the query
be escaped. This function quotes the other characters to
make them easier to read in log files."
(Source: http://dev.mysql.com/doc/mysql/en/mysql-real-escape-string.html)
--- Note 2 ---
\x1a = CTRL+Z.
mysql_real_escape_string() translates \x1a to \Z.
Backslashes (92) are used, not \e (27). Same as with addslashes().
--- Note 4 ---
Running mysql_real_escape_string() on already
backslashed data will add unwanted backslashes.
If PHP setting magic quotes is ON, POST, GET, FILES are
auto-slashed. See note 6 howto detect.
--- Note 5 ---
IF the connection to MySQL FAILS and the real
mysql_real_escape_string-API can't be run, then PHP
seems to slash only \-chars and '-chars in an home-made
way. Here are comments from the PHP 5.0.4 sourcecode:
"/* mysql_real_escape_string failed, just do my own escaping then */
/* replace \ with \\ */"
/* ' with '' */"
(Source: php-5.0.4\ext\dbx\dbx_mysql.c (lines 276-294))
Quite scary?
--- Note 6 ---
"A 'Best Practice' query: [...]
function quote_smart($value)
{
// Stripslashes
if (get_magic_quotes_gpc()) {
$value = stripslashes($value);
}
// Quote if not integer
if (!is_numeric($value)) {
$value = "'" . mysql_real_escape_string($value) . "'";
}
return $value;
}
"
(Source: http://www.zend.com/manual/function.mysql-real-escape-string.php)
--- Note 7 ---
A function that only slashes unslashed data would be appreciated.
If I come up with something I will post a note.