DB_DataObject function 'escape'
| From: | Norbert Mocsnik | Date: | Tue, 23 Mar 2004 00:04:00 +0000 |
| Subject: | DB_DataObject function 'escape' | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-26646@lists.php.net to get a copy of this message | ||
Hello,
I'm working on a generic form generator for formbuilder and it's quite complex so I had to write my own 'where' condition generator. I pass the whole generated stuff to dataobject using only one call to $do->whereAdd($where). This works fine.
When generating the parts of the condition, I tried to call $do->escape($fieldvalue) for each field in the table, regardless of field type (DB_DATAOBJECT_STR / DB_DATAOBJECT_INT only for now). It works fine with strings, however it breaks the compatiblity with numbers (which doesn't need quoting) that DB::quote() offers. If a number is passed to DB::quote(), the return value will be the number itself without any quotation marks. The current implementation of the corresponding DB_DataObject::escape() function simply cuts off the first and last characters of this value, so it makes the number 'shorter' by two digits, which is not the expected result.
I'd simply like to ask you what the main reason was for trimming the leading/trailing quotation marks from DB qouted strings (using substr(), see footnote). I can live with this, however, I think this is not the expected functionality and this should be considered to be a bug.
I'll be glad to write a patch if you agree with me.
Regards,
Norbert
--
DB_DataObject.php
current version (1.245) from the cvs
(substr() part never changed imho)
function escape($string)
{
global $_DB_DATAOBJECT;
$this->_connect();
$DB = &$_DB_DATAOBJECT['CONNECTIONS'][$this->_database_dsn_md5];
return substr($DB->quote($string),1,-1);}