Re: DB->quote
| From: | Tomas V.V.Cox | Date: | Wed, 22 Aug 2001 21:40:08 +0000 |
| Subject: | Re: DB->quote | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-1667@lists.php.net to get a copy of this message | ||
Edin Kadribasic wrote:
>
> >
> > There were a long thread here about the quote system and ended with this
> > option. Is the standar selected by others database abstraction layers
> > like Perl DBI and will put the single quotes only when needed.
> >
> > old method (select by hand when to put single quotes):
> > $sql = "insert into foo values ('" . $db->quoteString($name) .
> > "')";
> > new method (automatic put single quotes when needed):
> > $sql = "insert into foo values (" . $db->quote($name) . ")";
>
> You realize that having "old method" and "new method" in a minor revision
> change of PHP means breaking backwards compatiblity of every single PHP
> script that uses quoteString() method. It will require major effort on
> developers part to make their applications work again. It also makes
> writting PHP code version dependant.
>
> I suggest that either:
>
> 1. method quoteString() disappears from DB/common.php since its inline
> documentation is misleading "(preserved for compatibility issues)"
>
> 2. method quoteString() is changed to
>
> return substr($this->quote($string),1,-1);
>
> which would be backward compatible.
Umm.. I see no problem for doing that, anyone?
The solution should be (remember that some values aren't quoted now):
$string = $this->quote($string);
if (strpos($string,"'") !== false) {
return substr($string,1,-1);
}
return $string;
Tomas V.V.Cox