Re: Having escaped quotes problem in DB_DataObject (I think)
| From: | Alan Knowles | Date: | Sat, 16 Aug 2003 03:41:15 +0000 |
| Subject: | Re: Having escaped quotes problem in DB_DataObject (I think) | ||
| References: | 1 | Groups: | php.pear.general php.pear.general |
| Request: | Send a blank email to pear-general+get-7230@lists.php.net to get a copy of this message | ||
basically turn magic_quotes_gpc off, or dont send escaped values into DataObjects.. - It escapes values.
I have had a few comments about this. - The current logic may be that
I add a check to DataObjects that checks if magic_quotes is on, and issues a warning if you havent set a variable.
something like..
define('DB_DATAOBJECT_I_KNOW_MAGIC_QUOTES_IS_ON_AND_IM_WILLING_TO_SORT_OUT_THE_MESS_IT_CREATES',
true);
:)
Regards
Alan
Andy Crain wrote:
My apologies in advance if this is a DB rather than a DB_DataObject question, but here it is: I'm using DataObject's insert() to run inserts, and when values being inserted contain single or double quotes, they're being escaped twice, it seems, when the query is built. So, [this has quote's] becomes [this has quote\\\'s], as in: INSERT INTO table (a,b,c,quote) VALUES ('one' , 2 , 'three' , 'this has quote\\\'s ') I have magic_quotes_gpc = On in php.ini and so don't usually worry about this. I looked through DataObjects code and couldn't find out where this occurs; I do see that DB's quote() is called, but that seems to escape Sybase style, i.e. ' to ''. Could someone please point me in the right direction? Thanks, Andy