Re: Re: [ANNOUNCEMENT] DB_DataObject-0.9 (stable) Released.

From: Date: Fri, 06 Dec 2002 21:23:36 +0000
Subject: Re: Re: [ANNOUNCEMENT] DB_DataObject-0.9 (stable) Released.
References: 1 2 3  Groups: php.pear.dev php.pear.general 
Request: Send a blank email to pear-dev+get-11418@lists.php.net to get a copy of this message
The correct way to deal with this is to check ini_get("magic_quotes_gpc") and strip/addslashes where necessary. What about using $dbh->quote() or quoteString()? - Stig On Fri, 2002-12-06 at 10:37, Alan Knowles wrote: > You are not supposed to use it with magic quotes - (it should really > check/ give you a warning about that).. > > Regards > Alan > > > Jeroen Houben wrote: > > >I noticed that inserted strings automatically get escaped: > > > > if ($v & DB_DATAOBJECT_STR) { > > $rightq .= "'" . addslashes($this->$k). "' > > "; > > continue; > > } > > > >But retrieved string don't automatically "unescaped" using stripslashes(). > >Also, all retrieved data is of the type String, even numeric values. Was this done > >intentionally? > > > >Cheers > >Jeroen > > > > > > > > > > > >

« previous php.pear.dev (#11418) next »