RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - politics aside:-)

From: Date: Tue, 19 Mar 2002 17:39:36 +0000
Subject: RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - politics aside:-)
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-5045@lists.php.net to get a copy of this message
> The other advantage is that you don't need to quote your strings yourself, > avoiding any security problems from tainted data (eg. $_GET and $_POST > strings). Aeh how so? I am aware of the problem of possible "tainted" data but where does the data get handled differently from a "normal" query? Best regards, Lukas Smith smith@dybnet.de _______________________________ DybNet Internet Solutions GbR Alt Moabit 89 10559 Berlin Germany Tel. : +49 30 83 22 50 00 Fax : +49 30 83 22 50 07 www.dybnet.de info@dybnet.de _______________________________ > -----Original Message----- > From: John Lim [mailto:heyjohnlim@yahoo.com] > Sent: Tuesday, March 19, 2002 6:40 PM > To: pear-dev@lists.php.net > Subject: Re: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - > politics aside:-) > > > > Could someone explain to me the real advantage behind prepare? > > I think I know part of it but could someone just give me an entire run > > down? :-) > > > > Lukas Smith > > smith@dybnet.de > > Hi Lukas, > > Prepare() parses and compiles your sql once. So if you have an insert > statement > that is suppose to be run 1000 times in a loop, imagine saving the compile > time > by doing a Prepare() once only. It's a bit like using Zend Cache or APC > for > SQL. > > The other advantage is that you don't need to quote your strings yourself, > avoiding any security problems from tainted data (eg. $_GET and $_POST > strings). > > Regards, John > > > > -- > PEAR Development Mailing List (http://pear.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.pear.dev (#5045) next »