RE: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think)

From: Date: Sat, 16 Aug 2003 18:48:03 +0000
Subject: RE: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think)
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-7248@lists.php.net to get a copy of this message
Alan, Thanks. I went ahead and turned off magic_quotes_gpc. I'd been considering it anyway, just putting it off. Still, it might be nice to do. I was kind of surprised to see there isn't such a test in DB already. Or maybe just override quote()? Maybe that's too much for a small problem though... function quote($str) { if( get_magic_quotes_gpc() && ( strtolower(gettype($str) ) == 'string') ) { return "'$str'"; } else { return $__DB->quote($str); } } > -----Original Message----- > From: Alan Knowles [mailto:alan@akbkhome.com] > Sent: Friday, August 15, 2003 11:41 PM > To: pear-general@lists.php.net; Andy Crain > Cc: pear-general@lists.php.net > Subject: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I > think) > > basically turn magic_quotes_gpc off, or dont send escaped values into > DataObjects.. - It escapes values. > > I have had a few comments about this. - The current logic may be that > I add a check to DataObjects that checks if magic_quotes is on, and > issues a warning if you havent set a variable. > > something like.. > > define('DB_DATAOBJECT_I_KNOW_MAGIC_QUOTES_IS_ON_AND_IM_WILLING_TO_SORT_O UT > _THE_MESS_IT_CREATES', > true); > > :) > > Regards > Alan > > > > > > Andy Crain wrote: > > My apologies in advance if this is a DB rather than a DB_DataObject > > question, but here it is: I'm using DataObject's insert() to run > > inserts, and when values being inserted contain single or double quotes, > > they're being escaped twice, it seems, when the query is built. So, > > [this has quote's] becomes [this has quote\\\'s], as in: > > > > INSERT INTO table (a,b,c,quote) VALUES ('one' , 2 , 'three' , > > 'this has > > quote\\\'s ') > > > > I have magic_quotes_gpc = On in php.ini and so don't usually worry about > > this. I looked through DataObjects code and couldn't find out where this > > occurs; I do see that DB's quote() is called, but that seems to escape > > Sybase style, i.e. ' to ''. Could someone please point me in the right > > direction? > > Thanks, > > Andy > > > > > > > > > > > -- > PEAR General Mailing List (http://pear.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.pear.general (#7248) next »