Re: Bugs in PEAR::DB
| From: | Markus Fischer | Date: | Wed, 11 Jul 2001 17:58:38 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-639@lists.php.net to get a copy of this message | ||
On Wed, Jul 11, 2001 at 08:09:33PM +0200, Tomas V.V.Cox wrote :
> I think we are mixing concepts. Magic_quotes only adds slashes and is
> not a good quote system for inserting it in queries. For example:
> a string like:
> --hello "this is 'a string--
> might be quoted by magic_quotes_gpc:
> --hello \"this is \'a string--
> while for example PostgreSQL needs:
> --hello "this is ''a string--
>
> This is why I think that people should quote the data with native
> $db->quoteString() instead of relaying in magic_quotes. Also in the
> magic_quotes doc says that it will escape NULs (I don't know what that
> means) while we need to transform a null (php constant) value to a
> "NULL" string.
If you enable magic_quotes_sybase in PHP.INI strings containing
"'" are properly escaped to "''' (everyone using databases like
postgres/oracle/sybase of course should be aware of that).
- Markus
--
Markus Fischer, http://guru.josefine.at/~mfischer/
EMail: mfischer@guru.josefine.at
PGP Public Key: http://guru.josefine.at/~mfischer/C2272BD0.asc
PGP Fingerprint: D3B0 DD4F E12B F911 3CE1 C2B5 D674 B445 C227 2BD0