RE: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think)

From: Date: Sun, 17 Aug 2003 19:09:10 +0000
Subject: RE: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think)
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-7261@lists.php.net to get a copy of this message
Ah. Good point. > -----Original Message----- > From: Alan Knowles [mailto:alan@akbkhome.com] > Sent: Sunday, August 17, 2003 9:41 AM > To: pear-general@lists.php.net; Andy Crain > Cc: pear-general@lists.php.net > Subject: Re: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I > think) > > Andy Crain wrote: > > Alan, > > Thanks. I went ahead and turned off magic_quotes_gpc. I'd been > > considering it anyway, just putting it off. Still, it might be nice to > > do. I was kind of surprised to see there isn't such a test in DB > > already. > > Or maybe just override quote()? Maybe that's too much for a small > > problem though... > > > > function quote($str) > > { > > if( get_magic_quotes_gpc() && ( strtolower(gettype($str) ) == > > 'string') ) { > > return "'$str'"; > > } else { > > return $__DB->quote($str); > > } > > } > > This would make too many assumptions.. :) if you read a piece of data in > from parsing a web page, eg. file_get_contents('www.google.com').. and > it contained data that needed quoting, but you had magic_quotes on... - > you can see what I mean by willing to sort out the mess :) > > Regards > Alan > > > > > > > >>-----Original Message----- > >>From: Alan Knowles [mailto:alan@akbkhome.com] > >>Sent: Friday, August 15, 2003 11:41 PM > >>To: pear-general@lists.php.net; Andy Crain > >>Cc: pear-general@lists.php.net > >>Subject: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I > >>think) > >> > >>basically turn magic_quotes_gpc off, or dont send escaped values into > >>DataObjects.. - It escapes values. > >> > >>I have had a few comments about this. - The current logic may be that > >>I add a check to DataObjects that checks if magic_quotes is on, and > >>issues a warning if you havent set a variable. > >> > >>something like.. > >> > >> > > > > define('DB_DATAOBJECT_I_KNOW_MAGIC_QUOTES_IS_ON_AND_IM_WILLING_TO_SORT_O > > UT > > > >>_THE_MESS_IT_CREATES', > >>true); > >> > >>:) > >> > >>Regards > >>Alan > >> > >> > >> > >> > >> > >>Andy Crain wrote: > >> > >>>My apologies in advance if this is a DB rather than a DB_DataObject > >>>question, but here it is: I'm using DataObject's insert() to run > >>>inserts, and when values being inserted contain single or double > > > > quotes, > > > >>>they're being escaped twice, it seems, when the query is built. So, > >>>[this has quote's] becomes [this has quote\\\'s], as in: > >>> > >>>INSERT INTO table (a,b,c,quote) VALUES ('one' , 2 , 'three' , > >>>'this > > > > has > > > >>>quote\\\'s ') > >>> > >>>I have magic_quotes_gpc = On in php.ini and so don't usually worry > > > > about > > > >>>this. I looked through DataObjects code and couldn't find out where > > > > this > > > >>>occurs; I do see that DB's quote() is called, but that seems to > > > > escape > > > >>>Sybase style, i.e. ' to ''. Could someone please point me in the > > > > right > > > >>>direction? > >>>Thanks, > >>>Andy > >>> > >>> > >>> > >>> > >> > >> > >>-- > >>PEAR General Mailing List (http://pear.php.net/) > >>To unsubscribe, visit: http://www.php.net/unsub.php > > > > > > > > > > > -- > PEAR General Mailing List (http://pear.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.pear.general (#7261) next »