RE: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think)
| From: | Andy Crain | Date: | Sun, 17 Aug 2003 19:09:10 +0000 |
| Subject: | RE: [PEAR] Re: Having escaped quotes problem in DB_DataObject (I think) | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-7261@lists.php.net to get a copy of this message | ||
Ah. Good point.
> -----Original Message-----
> From: Alan Knowles [mailto:alan@akbkhome.com]
> Sent: Sunday, August 17, 2003 9:41 AM
> To: pear-general@lists.php.net; Andy Crain
> Cc: pear-general@lists.php.net
> Subject: Re: [PEAR] Re: Having escaped quotes problem in DB_DataObject
(I
> think)
>
> Andy Crain wrote:
> > Alan,
> > Thanks. I went ahead and turned off magic_quotes_gpc. I'd been
> > considering it anyway, just putting it off. Still, it might be nice
to
> > do. I was kind of surprised to see there isn't such a test in DB
> > already.
> > Or maybe just override quote()? Maybe that's too much for a small
> > problem though...
> >
> > function quote($str)
> > {
> > if( get_magic_quotes_gpc() && ( strtolower(gettype($str) ) ==
> > 'string') ) {
> > return "'$str'";
> > } else {
> > return $__DB->quote($str);
> > }
> > }
>
> This would make too many assumptions.. :) if you read a piece of data
in
> from parsing a web page, eg. file_get_contents('www.google.com').. and
> it contained data that needed quoting, but you had magic_quotes on...
-
> you can see what I mean by willing to sort out the mess :)
>
> Regards
> Alan
>
>
> >
> >
> >>-----Original Message-----
> >>From: Alan Knowles [mailto:alan@akbkhome.com]
> >>Sent: Friday, August 15, 2003 11:41 PM
> >>To: pear-general@lists.php.net; Andy Crain
> >>Cc: pear-general@lists.php.net
> >>Subject: [PEAR] Re: Having escaped quotes problem in DB_DataObject
(I
> >>think)
> >>
> >>basically turn magic_quotes_gpc off, or dont send escaped values
into
> >>DataObjects.. - It escapes values.
> >>
> >>I have had a few comments about this. - The current logic may be
that
> >>I add a check to DataObjects that checks if magic_quotes is on, and
> >>issues a warning if you havent set a variable.
> >>
> >>something like..
> >>
> >>
> >
> >
define('DB_DATAOBJECT_I_KNOW_MAGIC_QUOTES_IS_ON_AND_IM_WILLING_TO_SORT_O
> > UT
> >
> >>_THE_MESS_IT_CREATES',
> >>true);
> >>
> >>:)
> >>
> >>Regards
> >>Alan
> >>
> >>
> >>
> >>
> >>
> >>Andy Crain wrote:
> >>
> >>>My apologies in advance if this is a DB rather than a DB_DataObject
> >>>question, but here it is: I'm using DataObject's insert() to run
> >>>inserts, and when values being inserted contain single or double
> >
> > quotes,
> >
> >>>they're being escaped twice, it seems, when the query is built. So,
> >>>[this has quote's] becomes [this has quote\\\'s], as in:
> >>>
> >>>INSERT INTO table (a,b,c,quote) VALUES ('one' , 2 , 'three' ,
> >>>'this
> >
> > has
> >
> >>>quote\\\'s ')
> >>>
> >>>I have magic_quotes_gpc = On in php.ini and so don't usually worry
> >
> > about
> >
> >>>this. I looked through DataObjects code and couldn't find out where
> >
> > this
> >
> >>>occurs; I do see that DB's quote() is called, but that seems to
> >
> > escape
> >
> >>>Sybase style, i.e. ' to ''. Could someone please point me in the
> >
> > right
> >
> >>>direction?
> >>>Thanks,
> >>>Andy
> >>>
> >>>
> >>>
> >>>
> >>
> >>
> >>--
> >>PEAR General Mailing List (http://pear.php.net/)
> >>To unsubscribe, visit: http://www.php.net/unsub.php
> >
> >
> >
> >
>
>
> --
> PEAR General Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php