DB method for escaping % and _
| From: | David Sklar | Date: | Tue, 01 Apr 2003 16:09:13 +0000 |
| Subject: | DB method for escaping % and _ | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-14767@lists.php.net to get a copy of this message | ||
I'd like to add the capability to DB to escape the wildcards % and _ in
values replacing placeholders or values passed to DB::quote(). This prevents
wildcards in user input from retrieving unexpected results. What would be
the best approach for me to take?
- add a new method to class DB that backslash-escapes % and _ (which
database-specific classes can override)
- modify DB::quote() (and the quote() method in database-specific classes)
to also escape % and _ if an additional parameter is passed or a global
setting (like fetchmode) is set?
- something else?
Ideally, I'd like to be able to do this:
$dbh->query('SELECT * FROM foo WHERE bar LIKE ?',array($_REQUEST['baz']));
and if $_REQUEST['baz'] is "It's %great%", have the query turned into
SELECT * FROM foo WHERE bar LIKE 'It\'s \%great\%'
(or SELECT * FROM foo WHERE bar LIKE 'It''s \%great\%' if that's
what's
appropriate for the database.)
Thanks,
David