Re: Bugs in PEAR::DB

From: Date: Wed, 11 Jul 2001 17:58:38 +0000
Subject: Re: Bugs in PEAR::DB
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-639@lists.php.net to get a copy of this message
On Wed, Jul 11, 2001 at 08:09:33PM +0200, Tomas V.V.Cox wrote : > I think we are mixing concepts. Magic_quotes only adds slashes and is > not a good quote system for inserting it in queries. For example: > a string like: > --hello "this is 'a string-- > might be quoted by magic_quotes_gpc: > --hello \"this is \'a string-- > while for example PostgreSQL needs: > --hello "this is ''a string-- > > This is why I think that people should quote the data with native > $db->quoteString() instead of relaying in magic_quotes. Also in the > magic_quotes doc says that it will escape NULs (I don't know what that > means) while we need to transform a null (php constant) value to a > "NULL" string. If you enable magic_quotes_sybase in PHP.INI strings containing "'" are properly escaped to "''' (everyone using databases like postgres/oracle/sybase of course should be aware of that). - Markus -- Markus Fischer, http://guru.josefine.at/~mfischer/ EMail: mfischer@guru.josefine.at PGP Public Key: http://guru.josefine.at/~mfischer/C2272BD0.asc PGP Fingerprint: D3B0 DD4F E12B F911 3CE1 C2B5 D674 B445 C227 2BD0

« previous php.pear.dev (#639) next »