Re: Quote String

From: Date: Fri, 06 Jul 2001 01:56:03 +0000
Subject: Re: Quote String
References: 1 2 3 4 5 6 7  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-563@lists.php.net to get a copy of this message
At 3:41 AM +0200 7/6/01, Tomas V.V.Cox wrote:
Paul DuBois wrote:
I guess the question isn't as simple as I thought. Initially, I thought this might do it:
     // {{{ quoteString()
     function quoteString($string)
     {
         return ($string == null ? "NULL" : mysql_escape_string($string)) ;
     }
The correct sintaxis should be: return ($string === null) ? "NULL" : mysql_escape_string($string);
I don't see any semantic difference. They both return the same result.
"===" means equal value and equal type. If $string = 0 it will be treated as NULL when 0 is a value different from '' (null string).
Oops! I missed that it was a triple equal.
However, the problem is that quoteString() doesn't add quotes
around non-NULL values. So it doesn't really act like DBI's quote() at all.
Why not? mysql_escape_string() problem?
It's not a problem of implementation, really, just a difference of intent. mysql_escape_string() is intended to make the string safe for inserting between quotes in a query. The result doesn't include the surrounding quotes.
Yeah, excuse me, I meant: return ($string === null) ? "NULL" : "'".mysql_escape_string($string)."'"; Tomas V.V.Cox
That's *exactly* what would be the most useful implementation of quoteString() for MySQL. -- Paul DuBois, paul@snake.net

« previous php.pear.dev (#563) next »