Re: Re: Having escaped quotes problem in DB_DataObject (I think)

From: Date: Sun, 17 Aug 2003 13:41:03 +0000
Subject: Re: Re: Having escaped quotes problem in DB_DataObject (I think)
References: 1 2  Groups: php.pear.general php.pear.general 
Request: Send a blank email to pear-general+get-7257@lists.php.net to get a copy of this message
Andy Crain wrote:
Alan, Thanks. I went ahead and turned off magic_quotes_gpc. I'd been considering it anyway, just putting it off. Still, it might be nice to do. I was kind of surprised to see there isn't such a test in DB already. Or maybe just override quote()? Maybe that's too much for a small problem though... function quote($str) { if( get_magic_quotes_gpc() && ( strtolower(gettype($str) ) == 'string') ) { return "'$str'"; } else { return $__DB->quote($str); } }
This would make too many assumptions.. :) if you read a piece of data in from parsing a web page, eg. file_get_contents('www.google.com').. and it contained data that needed quoting, but you had magic_quotes on... - you can see what I mean by willing to sort out the mess :) Regards Alan
-----Original Message----- From: Alan Knowles [mailto:alan@akbkhome.com] Sent: Friday, August 15, 2003 11:41 PM To: pear-general@lists.php.net; Andy Crain Cc: pear-general@lists.php.net Subject: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think) basically turn magic_quotes_gpc off, or dont send escaped values into DataObjects.. - It escapes values. I have had a few comments about this. - The current logic may be that I add a check to DataObjects that checks if magic_quotes is on, and issues a warning if you havent set a variable. something like..
define('DB_DATAOBJECT_I_KNOW_MAGIC_QUOTES_IS_ON_AND_IM_WILLING_TO_SORT_O UT
_THE_MESS_IT_CREATES', true); :) Regards Alan Andy Crain wrote:
My apologies in advance if this is a DB rather than a DB_DataObject question, but here it is: I'm using DataObject's insert() to run inserts, and when values being inserted contain single or double
quotes,
they're being escaped twice, it seems, when the query is built. So, [this has quote's] becomes [this has quote\\\'s], as in: INSERT INTO table (a,b,c,quote) VALUES ('one' , 2 , 'three' , 'this
has
quote\\\'s ') I have magic_quotes_gpc = On in php.ini and so don't usually worry
about
this. I looked through DataObjects code and couldn't find out where
this
occurs; I do see that DB's quote() is called, but that seems to
escape
Sybase style, i.e. ' to ''. Could someone please point me in the
right
direction? Thanks, Andy
-- PEAR General Mailing List (http://pear.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php


« previous php.pear.general (#7257) next »