Re: Quote String
| From: | Colin Viebrock | Date: | Fri, 06 Jul 2001 02:56:00 +0000 |
| Subject: | Re: Quote String | ||
| References: | 1 2 3 4 5 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-564@lists.php.net to get a copy of this message | ||
> The correct sintaxis should be:
>
> return ($string === null) ? "NULL" : mysql_escape_string($string);
>
> > However, the problem is that quoteString() doesn't add quotes
> > around non-NULL values. So it doesn't really act like DBI's quote()
> > at all.
Uh ... shouldn't it be:
return ($string===null) ? "NULL" : "'" . mysql_escape_string($string) .
"'";
In the quoted example, there is no difference if $string=="NULL" or $string
*is* NULL.
Also, I have 2 functions I use all the time: makeSQLInsert() and
makeSQLUpdate(), which basically take an associative array and return:
"(key1, key2, key3) VALUES ('value1','value2','value3')"
for makeSQLInsert() and:
"key1='value1', key2='value2', key3='value3'"
for makeSQLUpdate ... both with the proper quoting and escaping. If your
keyname starts with '%', then the value is treated like a mysql command and
not quoted, eg.:
$data = array(
'name' => 'Colin',
'%date_added' => 'NOW()'
);
echo makeSQLInsert($data);
That would return:
(name, date_added) VALUES ('Colin', NOW())
Anyway, I use these so much, I'm wondering if there is a place for them in
PEAR.
- Colin
- Colin