Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #2242

Re: Form fields to database and back?

Message-Id <4727679.ypaU67uLZW@PointedEars.de>
From Thomas 'PointedEars' Lahn <PointedEars@web.de>
Organization PointedEars Software (PES)
Date 2011-06-18 08:35 +0200
Subject Re: Form fields to database and back?
Newsgroups comp.lang.php
References <j48lv6prpshk57ora2dsp6b2lvp16vkvtu@4ax.com> <ite935$1b5$1@dont-email.me> <plelv6lp4m78uv2tg5mjtm9bd5f13douk5@4ax.com> <1655216.aK4W3vaeNJ@PointedEars.de> <sppnv6tecikiudrbhkq4v4rcacioqihvnu@4ax.com>
Followup-To comp.lang.php

Followups directed to: comp.lang.php

Show all headers | View raw


bobmct wrote:

> From field to database I used mysql_real_escape_string.
> 
> When I look at the actual data stored in the db field that function
> inserted backslashes before each double quote.
> 
> To display the retrieved db field I ran it through htmlspecialchars()
> but the backslashes  still remained.  I had to use stripslashes to
> remove them.

Then you are doing something wrong.  mysql_real_escape_string() – AISB, 
prepared statements (PS) with MySQLi or PDO are preferable to that – only 
escapes the data for the query, so that SQL code injection is prevented.
It does _not_ change the data to be stored.  So when you retrieve the data 
you should not need to unescape anything.  Perhaps you have used 
mysql_real_escape_string() on the retrieved data also, but that is _not_ its 
purpose.

> Works for now.

By chance.  mysql_real_escape_string() does more than addslashes(), which is 
why it is preferable to that.  (And PS are preferable to it because they 
consider the type automatically, among other advantages.)
 

PointedEars
-- 
Use any version of Microsoft Frontpage to create your site.
(This won't prevent people from viewing your source, but no one
will want to steal it.)
  -- from <http://www.vortex-webdesign.com/help/hidesource.htm> (404-comp.)

Back to comp.lang.php | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-16 20:36 -0400
  Re: Form fields to database and back? The Natural Philosopher <tnp@invalid.invalid> - 2011-06-17 01:43 +0100
    Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 21:03 -0400
  Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 21:02 -0400
    Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-16 22:34 -0400
      Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 23:50 -0400
        Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-17 07:09 -0400
          Re: Form fields to database and back? bobm3@worthless.info - 2011-06-17 15:18 +0000
            Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-17 16:44 -0400
      Re: Form fields to database and back? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-06-17 13:28 +0200
      Re: Form fields to database and back? Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-06-17 22:03 +0200
        Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-17 19:52 -0400
          Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-17 21:01 -0400
            Re: Form fields to database and back? Captain Paralytic <paul_lautman@yahoo.com> - 2011-06-22 09:05 -0700
              Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-22 13:15 -0400
          Re: Form fields to database and back? Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-06-18 08:35 +0200

csiph-web