Re: DB/common: quote() and the ' at the end/beginning

From: Date: Wed, 26 Sep 2001 23:37:16 +0000
Subject: Re: DB/common: quote() and the ' at the end/beginning
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-2072@lists.php.net to get a copy of this message
Alexander Skwar wrote: > > Now, this is obviosuly bad. $like should be quoted. But, running > DB::quote() on it, returns 'test\'ing' (with the quotes, of course). > So, this would be wrong: > > $like_quoted = $dbh->quote($like); > $SQL = 'SELECT * FROM Foo WHERE Bar LIKE "%' . $like_quoted . > '%"'; > > This would be wrong, because the $SQL would contain: > > ...LIKE "%'test''ing'%" > > (with the quotes). > > The problem is, that ' are added to the beginning and end of the > returned string. > This problem was detected time ago and it's fixed in lastest revisions of pear/DB/common.php. Use DB::quoteString() for getting only the quoted string (tes't => tes\'t) and DB::quote for the quoted string with "'" arround (tes't => 'test\'t'). Please update it. Thanks any way for the patches. Tomas V.V.Cox

« previous php.pear.dev (#2072) next »