DB method for escaping % and _

From: Date: Tue, 01 Apr 2003 16:09:13 +0000
Subject: DB method for escaping % and _
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-14767@lists.php.net to get a copy of this message
I'd like to add the capability to DB to escape the wildcards % and _ in values replacing placeholders or values passed to DB::quote(). This prevents wildcards in user input from retrieving unexpected results. What would be the best approach for me to take? - add a new method to class DB that backslash-escapes % and _ (which database-specific classes can override) - modify DB::quote() (and the quote() method in database-specific classes) to also escape % and _ if an additional parameter is passed or a global setting (like fetchmode) is set? - something else? Ideally, I'd like to be able to do this: $dbh->query('SELECT * FROM foo WHERE bar LIKE ?',array($_REQUEST['baz'])); and if $_REQUEST['baz'] is "It's %great%", have the query turned into SELECT * FROM foo WHERE bar LIKE 'It\'s \%great\%' (or SELECT * FROM foo WHERE bar LIKE 'It''s \%great\%' if that's what's appropriate for the database.) Thanks, David

« previous php.pear.dev (#14767) next »