RE: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think)
| From: | Andy Crain | Date: | Sat, 16 Aug 2003 18:48:03 +0000 |
| Subject: | RE: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think) | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-7248@lists.php.net to get a copy of this message | ||
Alan,
Thanks. I went ahead and turned off magic_quotes_gpc. I'd been
considering it anyway, just putting it off. Still, it might be nice to
do. I was kind of surprised to see there isn't such a test in DB
already.
Or maybe just override quote()? Maybe that's too much for a small
problem though...
function quote($str)
{
if( get_magic_quotes_gpc() && ( strtolower(gettype($str) ) ==
'string') ) {
return "'$str'";
} else {
return $__DB->quote($str);
}
}
> -----Original Message-----
> From: Alan Knowles [mailto:alan@akbkhome.com]
> Sent: Friday, August 15, 2003 11:41 PM
> To: pear-general@lists.php.net; Andy Crain
> Cc: pear-general@lists.php.net
> Subject: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I
> think)
>
> basically turn magic_quotes_gpc off, or dont send escaped values into
> DataObjects.. - It escapes values.
>
> I have had a few comments about this. - The current logic may be that
> I add a check to DataObjects that checks if magic_quotes is on, and
> issues a warning if you havent set a variable.
>
> something like..
>
>
define('DB_DATAOBJECT_I_KNOW_MAGIC_QUOTES_IS_ON_AND_IM_WILLING_TO_SORT_O
UT
> _THE_MESS_IT_CREATES',
> true);
>
> :)
>
> Regards
> Alan
>
>
>
>
>
> Andy Crain wrote:
> > My apologies in advance if this is a DB rather than a DB_DataObject
> > question, but here it is: I'm using DataObject's insert() to run
> > inserts, and when values being inserted contain single or double
quotes,
> > they're being escaped twice, it seems, when the query is built. So,
> > [this has quote's] becomes [this has quote\\\'s], as in:
> >
> > INSERT INTO table (a,b,c,quote) VALUES ('one' , 2 , 'three' ,
> > 'this
has
> > quote\\\'s ')
> >
> > I have magic_quotes_gpc = On in php.ini and so don't usually worry
about
> > this. I looked through DataObjects code and couldn't find out where
this
> > occurs; I do see that DB's quote() is called, but that seems to
escape
> > Sybase style, i.e. ' to ''. Could someone please point me in the
right
> > direction?
> > Thanks,
> > Andy
> >
> >
> >
> >
>
>
> --
> PEAR General Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php