Re: DB->quote
| From: | Tomas V.V.Cox | Date: | Wed, 22 Aug 2001 21:06:04 +0000 |
| Subject: | Re: DB->quote | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-1665@lists.php.net to get a copy of this message | ||
Edin Kadribasic wrote:
>
> I just checked out the lates php CVS just to find that all of my
> applications that are using Pear::DB were broken due to a change in
> quoteString method.
>
> The problem is that the new quote() method retuns a string with single
> quotes around it which I think it's a very bad idea.
>
>
> Even the function stub says:
>
> "Quote the given string so it can be safely used *within* string delimiters"
>
> It does not say anything about putting those delimiters within the returned
> string. Any reason for this change?
>
There were a long thread here about the quote system and ended with this
option. Is the standar selected by others database abstraction layers
like Perl DBI and will put the single quotes only when needed.
old method (select by hand when to put single quotes):
$sql = "insert into foo values ('" . $db->quoteString($name) .
"')";
new method (automatic put single quotes when needed):
$sql = "insert into foo values (" . $db->quote($name) . ")";
And yes, the in-line doc is outdated sorry.
Tomas V.V.Cox