Re: DB/common: quote() and the ' at the end/beginning
| From: | Tomas V.V.Cox | Date: | Wed, 26 Sep 2001 23:37:16 +0000 |
| Subject: | Re: DB/common: quote() and the ' at the end/beginning | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-2072@lists.php.net to get a copy of this message | ||
Alexander Skwar wrote:
>
> Now, this is obviosuly bad. $like should be quoted. But, running
> DB::quote() on it, returns 'test\'ing' (with the quotes, of course).
> So, this would be wrong:
>
> $like_quoted = $dbh->quote($like);
> $SQL = 'SELECT * FROM Foo WHERE Bar LIKE "%' . $like_quoted .
> '%"';
>
> This would be wrong, because the $SQL would contain:
>
> ...LIKE "%'test''ing'%"
>
> (with the quotes).
>
> The problem is, that ' are added to the beginning and end of the
> returned string.
>
This problem was detected time ago and it's fixed in lastest revisions
of pear/DB/common.php. Use DB::quoteString() for getting only the quoted
string (tes't => tes\'t) and DB::quote for the quoted string with "'"
arround (tes't => 'test\'t'). Please update it. Thanks any way for the
patches.
Tomas V.V.Cox