Jump to content

general function to clean value for for sql insert


Liquid Fire

Recommended Posts

Is there a function anyone knows of that will clean a value for a general sql insert(like the function works for mysql, mssql, postgresql, etc...).  Right now I have created a function in my data class

<?php
private function safe_value($value)
{
//we first need to replace any \" and \' that the user might have already escaped(like magic quotes) and the replace and remaining ',"
        $search = array('\"', '"', "\\'", "'");
        $replace = array('&#34;', '&#34;', '&#39;', '&#39;');
return str_replace($search, $replace, $value);
}
?>

is this good or do i need to replace extra characters?

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.