note 53767 deleted from function.mysql-real-escape-string by nlopess

From: Date: Fri, 29 Jul 2005 10:36:33 +0000
Subject: note 53767 deleted from function.mysql-real-escape-string by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-92721@lists.php.net to get a copy of this message
Note Submitter: dotpointer ---- --- Note 1 --- "Strictly speaking, MySQL requires only that backslash and the quote character used to quote the string in the query be escaped. This function quotes the other characters to make them easier to read in log files." (Source: http://dev.mysql.com/doc/mysql/en/mysql-real-escape-string.html) --- Note 2 --- \x1a = CTRL+Z. mysql_real_escape_string() translates \x1a to \Z. Backslashes (92) are used, not \e (27). Same as with addslashes(). --- Note 4 --- Running mysql_real_escape_string() on already backslashed data will add unwanted backslashes. If PHP setting magic quotes is ON, POST, GET, FILES are auto-slashed. See note 6 howto detect. --- Note 5 --- IF the connection to MySQL FAILS and the real mysql_real_escape_string-API can't be run, then PHP seems to slash only \-chars and '-chars in an home-made way. Here are comments from the PHP 5.0.4 sourcecode: "/* mysql_real_escape_string failed, just do my own escaping then */ /* replace \ with \\ */" /* ' with '' */" (Source: php-5.0.4\ext\dbx\dbx_mysql.c (lines 276-294)) Quite scary? --- Note 6 --- "A 'Best Practice' query: [...] function quote_smart($value) { // Stripslashes if (get_magic_quotes_gpc()) { $value = stripslashes($value); } // Quote if not integer if (!is_numeric($value)) { $value = "'" . mysql_real_escape_string($value) . "'"; } return $value; } " (Source: http://www.zend.com/manual/function.mysql-real-escape-string.php) --- Note 7 --- A function that only slashes unslashed data would be appreciated. If I come up with something I will post a note.

« previous php.notes (#92721) next »