Re: Quote String
| From: | Tomas V.V.Cox | Date: | Fri, 06 Jul 2001 01:41:55 +0000 |
| Subject: | Re: Quote String | ||
| References: | 1 2 3 4 5 6 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-562@lists.php.net to get a copy of this message | ||
Paul DuBois wrote:
>
> > >
> > > I guess the question isn't as simple as I thought. Initially, I
> > > thought this might do it:
> > >
> > > // {{{ quoteString()
> > >
> > > function quoteString($string)
> > > {
> > > return ($string == null ? "NULL" : mysql_escape_string($string)) ;
> > > }
> >
> > The correct sintaxis should be:
> >
> > return ($string === null) ? "NULL" : mysql_escape_string($string);
>
> I don't see any semantic difference. They both return the same result.
"===" means equal value and equal type. If $string = 0 it will be
treated as NULL when 0 is a value different from '' (null string).
> > > However, the problem is that quoteString() doesn't add quotes
> > > around non-NULL values. So it doesn't really act like DBI's quote()
> > > at all.
> >
> > Why not? mysql_escape_string() problem?
>
> It's not a problem of implementation, really, just a difference of intent.
> mysql_escape_string() is intended to make the string safe for inserting
> between quotes in a query. The result doesn't include the surrounding quotes.
>
Yeah, excuse me, I meant:
return ($string === null) ? "NULL" :
"'".mysql_escape_string($string)."'";
Tomas V.V.Cox