DB/common: quote() and the ' at the end/beginning

From: Date: Wed, 26 Sep 2001 21:17:22 +0000
Subject: DB/common: quote() and the ' at the end/beginning
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-2071@lists.php.net to get a copy of this message
Hi. I've got a problem with the DB::quote() function. With the old DB::quoteString() function, it was possible to quote any given string and use it as a string in a SQL statement. Not so with quote(). Consider the following: $like = "test'ing"; $SQL = 'SELECT * FROM Foo WHERE Bar LIKE "%' . $like . '%"'; Now, this is obviosuly bad. $like should be quoted. But, running DB::quote() on it, returns 'test\'ing' (with the quotes, of course). So, this would be wrong: $like_quoted = $dbh->quote($like); $SQL = 'SELECT * FROM Foo WHERE Bar LIKE "%' . $like_quoted . '%"'; This would be wrong, because the $SQL would contain: ..LIKE "%'test''ing'%" (with the quotes). The problem is, that ' are added to the beginning and end of the returned string. Would the proper solution be to use quoteString() instead? If so, then I'd suppose this statement should be removed from DB/common.php: | (preserved for compatibility issues, quote() is preffered) If not, then I propose the following change. It adds a new parameter $enclose_in_single_quotes to quote. If this parameter is set to FALSE, no ' are added. If it's set to TRUE or omitted, the quotes are added. The patch is below and also attached. --- common_old.php Wed Sep 26 22:58:13 2001 +++ common.php Wed Sep 26 23:01:23 2001 @@ -101,12 +101,18 @@ * * @param $string the input string to quote * + * @param bool Should single quotes be put around the string? + * * @return string The NULL string or the string quotes * in magic_quote_sybase style */ - function quote($string) + function quote($string, $enclose_in_single_quotes = TRUE) { - return ($string === null) ? 'NULL' : "'".str_replace("'", "''", $string)."'"; + if ($enclose_in_single_quotes){ + return ($string === null) ? 'NULL' : "'".str_replace("'", "''", $string)."'"; + } else { + return ($string === null) ? 'NULL' : str_replace("'", "''", $string); + } } // }}} --- mysql_old.php Wed Sep 26 23:02:48 2001 +++ mysql.php Wed Sep 26 23:04:43 2001 @@ -567,9 +567,10 @@ * Quote the given string so it can be safely used within string delimiters * in a query. * @param $string mixed Data to be quoted + * @param bool Should single quotes be put around the string? * @return mixed "NULL" string, quoted string or original data */ - function quote($str = null) + function quote($str = null, $enclose_in_single_quotes = TRUE) { switch (strtolower(gettype($str))) { case 'null': @@ -578,7 +579,11 @@ return $str; case 'string': default: - return "'".mysql_escape_string($str)."'"; + if ($enclose_in_single_quotes){ + return "'".mysql_escape_string($str)."'"; + } else { + return mysql_escape_string($str); + } } } // }}} @@ -715,4 +720,4 @@ // binmode } -?> \ No newline at end of file +?> --- pgsql_old.php Wed Sep 26 23:11:47 2001 +++ pgsql.php Wed Sep 26 23:11:43 2001 @@ -323,9 +323,10 @@ * Quote the given string so it can be safely used within string delimiters * in a query. * @param $string mixed Data to be quoted + * @param bool Should single quotes be put around the string? * @return mixed "NULL" string, quoted string or original data */ - function quote($str = null) + function quote($str = null, $enclose_in_single_quotes = TRUE) { switch (strtolower(gettype($str))) { case 'null': @@ -338,7 +339,11 @@ $str = str_replace("'", "''", $str); //PostgreSQL treats a backslash as an escape character. $str = str_replace('\\', '\\\\', $str); - return "'$str'"; + if ($enclose_in_single_quotes){ + return "'" . $str . "'"; + } else { + return $str; + } } } // }}} @@ -727,4 +732,4 @@ // tab-width: 4 // c-basic-offset: 4 // End: -?> \ No newline at end of file +?> Thanks, Alexander Skwar -- How to quote: http://learn.to/quote (german) http://quote.6x.to (english) Homepage: http://www.digitalprojects.com | http://www.iso-top.de iso-top.de - Die günstige Art an Linux Distributionen zu kommen Uptime: 3 days 11 hours 6 minutes

--- common_old.php Wed Sep 26 22:58:13 2001 +++ common.php Wed Sep 26 23:01:23 2001 @@ -101,12 +101,18 @@ * * @param $string the input string to quote * + * @param bool Should single quotes be put around the string? + * * @return string The NULL string or the string quotes * in magic_quote_sybase style */ - function quote($string) + function quote($string, $enclose_in_single_quotes = TRUE) { - return ($string === null) ? 'NULL' : "'".str_replace("'", "''", $string)."'"; + if ($enclose_in_single_quotes){ + return ($string === null) ? 'NULL' : "'".str_replace("'", "''", $string)."'"; + } else { + return ($string === null) ? 'NULL' : str_replace("'", "''", $string); + } } // }}} --- mysql_old.php Wed Sep 26 23:02:48 2001 +++ mysql.php Wed Sep 26 23:04:43 2001 @@ -567,9 +567,10 @@ * Quote the given string so it can be safely used within string delimiters * in a query. * @param $string mixed Data to be quoted + * @param bool Should single quotes be put around the string? * @return mixed "NULL" string, quoted string or original data */ - function quote($str = null) + function quote($str = null, $enclose_in_single_quotes = TRUE) { switch (strtolower(gettype($str))) { case 'null': @@ -578,7 +579,11 @@ return $str; case 'string': default: - return "'".mysql_escape_string($str)."'"; + if ($enclose_in_single_quotes){ + return "'".mysql_escape_string($str)."'"; + } else { + return mysql_escape_string($str); + } } } // }}} @@ -715,4 +720,4 @@ // binmode } -?> \ No newline at end of file +?> --- pgsql_old.php Wed Sep 26 23:11:47 2001 +++ pgsql.php Wed Sep 26 23:11:43 2001 @@ -323,9 +323,10 @@ * Quote the given string so it can be safely used within string delimiters * in a query. * @param $string mixed Data to be quoted + * @param bool Should single quotes be put around the string? * @return mixed "NULL" string, quoted string or original data */ - function quote($str = null) + function quote($str = null, $enclose_in_single_quotes = TRUE) { switch (strtolower(gettype($str))) { case 'null': @@ -338,7 +339,11 @@ $str = str_replace("'", "''", $str); //PostgreSQL treats a backslash as an escape character. $str = str_replace('\\', '\\\\', $str); - return "'$str'"; + if ($enclose_in_single_quotes){ + return "'" . $str . "'"; + } else { + return $str; + } } } // }}} @@ -727,4 +732,4 @@ // tab-width: 4 // c-basic-offset: 4 // End: -?> \ No newline at end of file +?>
« previous php.pear.dev (#2071) next »