{"id":18,"date":"2007-10-10T12:48:14","date_gmt":"2007-10-10T17:48:14","guid":{"rendered":"http:\/\/www.popmartian.com\/tipsntricks\/2007\/10\/10\/quick-character-escaping-in-php\/"},"modified":"2007-10-10T12:56:06","modified_gmt":"2007-10-10T17:56:06","slug":"quick-character-escaping-in-php","status":"publish","type":"post","link":"https:\/\/www.popmartian.com\/tipsntricks\/2007\/10\/10\/quick-character-escaping-in-php\/","title":{"rendered":"Quick Character Escaping in PHP"},"content":{"rendered":"<p>When writing PHP web apps, I tend to run in to a portability issue when dealing with SQL connectivity.  Since I can&#8217;t count on having the PEAR DB module available, I rolled my own set of functions to interact with a MySQL database.<\/p>\n<p>The problem lies in escaping characters in your SQL queries.  Do I <code>addslashes()<\/code>?  Is magic_quotes_gpc enabled?<\/p>\n<p>My quick-and-dirty solution is the following function:<\/p>\n<p><code><br \/>\nfunction request_cleanup()<br \/>\n{<br \/>\n&nbsp;&nbsp;if(get_magic_quotes_gpc() == 0)<br \/>\n&nbsp;&nbsp;{<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;foreach($_REQUEST as $req_key => $req_value)<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;{<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$_REQUEST[$req_key]=addslashes($_REQUEST[$req_key]);<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;}<br \/>\n&nbsp;&nbsp;}<br \/>\n}<br \/>\n<\/code><\/p>\n<p>By calling that function on every page that deals with inserting content in to the database, I know will will get my content escaped correctly.<\/p>\n<p>Of course it escapes all submitted content, including that which isn&#8217;t going in to the database so don&#8217;t forget to <code>stripslashes()<\/code> when you are working with data that doesn&#8217;t need it.<\/p>\n<p>Example:<br \/>\n<code><br \/>\nrequest_cleanup();<\/p>\n<p>$notes = $_REQUEST['notes '];<br \/>\n$confirmation = stripslashes($_REQUEST['notes ']);<\/p>\n<p>$SQL = \"INSERT INTO notes (note) VALUES ('$notes')\";<br \/>\nsql_proc($SQL);<\/p>\n<p>print \"Your note was: $confirmation\";<br \/>\n<\/code><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When writing PHP web apps, I tend to run in to a portability issue when dealing with SQL connectivity. Since I can&#8217;t count on having the PEAR DB module available, I rolled my own set of functions to interact with &hellip; <a href=\"https:\/\/www.popmartian.com\/tipsntricks\/2007\/10\/10\/quick-character-escaping-in-php\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,9,41],"tags":[],"class_list":["post-18","post","type-post","status-publish","format-standard","hentry","category-php","category-programming","category-sql"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/posts\/18","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/comments?post=18"}],"version-history":[{"count":1,"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/posts\/18\/revisions"}],"predecessor-version":[{"id":49,"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/posts\/18\/revisions\/49"}],"wp:attachment":[{"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/media?parent=18"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/categories?post=18"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.popmartian.com\/tipsntricks\/wp-json\/wp\/v2\/tags?post=18"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}