RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - politics aside:-)
| From: | Lukas Smith | Date: | Tue, 19 Mar 2002 17:39:36 +0000 |
| Subject: | RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - politics aside:-) | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-5045@lists.php.net to get a copy of this message | ||
> The other advantage is that you don't need to quote your strings
yourself,
> avoiding any security problems from tainted data (eg. $_GET and $_POST
> strings).
Aeh how so?
I am aware of the problem of possible "tainted" data but where does the
data get handled differently from a "normal" query?
Best regards,
Lukas Smith
smith@dybnet.de
_______________________________
DybNet Internet Solutions GbR
Alt Moabit 89
10559 Berlin
Germany
Tel. : +49 30 83 22 50 00
Fax : +49 30 83 22 50 07
www.dybnet.de info@dybnet.de
_______________________________
> -----Original Message-----
> From: John Lim [mailto:heyjohnlim@yahoo.com]
> Sent: Tuesday, March 19, 2002 6:40 PM
> To: pear-dev@lists.php.net
> Subject: Re: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear"
-
> politics aside:-)
>
>
> > Could someone explain to me the real advantage behind prepare?
> > I think I know part of it but could someone just give me an entire
run
> > down? :-)
> >
> > Lukas Smith
> > smith@dybnet.de
>
> Hi Lukas,
>
> Prepare() parses and compiles your sql once. So if you have an insert
> statement
> that is suppose to be run 1000 times in a loop, imagine saving the
compile
> time
> by doing a Prepare() once only. It's a bit like using Zend Cache or
APC
> for
> SQL.
>
> The other advantage is that you don't need to quote your strings
yourself,
> avoiding any security problems from tainted data (eg. $_GET and $_POST
> strings).
>
> Regards, John
>
>
>
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php