Re: Re: [ANNOUNCEMENT] DB_DataObject-0.9 (stable) Released.
| From: | Stig S. Bakken | Date: | Fri, 06 Dec 2002 21:23:36 +0000 |
| Subject: | Re: Re: [ANNOUNCEMENT] DB_DataObject-0.9 (stable) Released. | ||
| References: | 1 2 3 | Groups: | php.pear.dev php.pear.general |
| Request: | Send a blank email to pear-dev+get-11418@lists.php.net to get a copy of this message | ||
The correct way to deal with this is to check
ini_get("magic_quotes_gpc") and strip/addslashes where necessary. What
about using $dbh->quote() or quoteString()?
- Stig
On Fri, 2002-12-06 at 10:37, Alan Knowles wrote:
> You are not supposed to use it with magic quotes - (it should really
> check/ give you a warning about that)..
>
> Regards
> Alan
>
>
> Jeroen Houben wrote:
>
> >I noticed that inserted strings automatically get escaped:
> >
> > if ($v & DB_DATAOBJECT_STR) {
> > $rightq .= "'" . addslashes($this->$k). "'
> > ";
> > continue;
> > }
> >
> >But retrieved string don't automatically "unescaped" using stripslashes().
> >Also, all retrieved data is of the type String, even numeric values. Was this done
> >intentionally?
> >
> >Cheers
> >Jeroen
> >
> >
> >
> >
> >
>
>