Re: Re: Having escaped quotes problem in DB_DataObject (I think)
| From: | Alan Knowles | Date: | Sun, 17 Aug 2003 13:41:03 +0000 |
| Subject: | Re: Re: Having escaped quotes problem in DB_DataObject (I think) | ||
| References: | 1 2 | Groups: | php.pear.general php.pear.general |
| Request: | Send a blank email to pear-general+get-7257@lists.php.net to get a copy of this message | ||
Andy Crain wrote:
Alan, Thanks. I went ahead and turned off magic_quotes_gpc. I'd been considering it anyway, just putting it off. Still, it might be nice to do. I was kind of surprised to see there isn't such a test in DB already. Or maybe just override quote()? Maybe that's too much for a small problem though... function quote($str) { if( get_magic_quotes_gpc() && ( strtolower(gettype($str) ) == 'string') ) { return "'$str'"; } else { return $__DB->quote($str); } }This would make too many assumptions.. :) if you read a piece of data in from parsing a web page, eg. file_get_contents('www.google.com').. and it contained data that needed quoting, but you had magic_quotes on... - you can see what I mean by willing to sort out the mess :) Regards Alan
-----Original Message----- From: Alan Knowles [mailto:alan@akbkhome.com] Sent: Friday, August 15, 2003 11:41 PM To: pear-general@lists.php.net; Andy Crain Cc: pear-general@lists.php.net Subject: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think) basically turn magic_quotes_gpc off, or dont send escaped values into DataObjects.. - It escapes values. I have had a few comments about this. - The current logic may be that I add a check to DataObjects that checks if magic_quotes is on, and issues a warning if you havent set a variable. something like..define('DB_DATAOBJECT_I_KNOW_MAGIC_QUOTES_IS_ON_AND_IM_WILLING_TO_SORT_O UT_THE_MESS_IT_CREATES', true); :) Regards Alan Andy Crain wrote:quotes,My apologies in advance if this is a DB rather than a DB_DataObject question, but here it is: I'm using DataObject's insert() to run inserts, and when values being inserted contain single or doublehasthey're being escaped twice, it seems, when the query is built. So, [this has quote's] becomes [this has quote\\\'s], as in: INSERT INTO table (a,b,c,quote) VALUES ('one' , 2 , 'three' , 'thisaboutquote\\\'s ') I have magic_quotes_gpc = On in php.ini and so don't usually worrythisthis. I looked through DataObjects code and couldn't find out whereescapeoccurs; I do see that DB's quote() is called, but that seems torightSybase style, i.e. ' to ''. Could someone please point me in thedirection? Thanks, Andy-- PEAR General Mailing List (http://pear.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php