postgresql DB::quoteSmart
| From: | Thomas Jarosch | Date: | Sun, 28 Mar 2004 22:03:24 +0000 |
| Subject: | postgresql DB::quoteSmart | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-26838@lists.php.net to get a copy of this message | ||
Hi,
I stumbled across one thing while looking
through the DB database driver of postgresql:
The quoteSmart function does this to escape a string:
return str_replace("'", "''", str_replace('\\',
'\\\\', $str));
Is there a reason it shouldn't use pg_escape_string() for that?
I've checked the mysql backend,
it uses a real escape function.
Please CC: answers as I'm not on the list.
Best regards,
Thomas Jarosch