Grep Again (was: MySQL UPDATE)
This WebDNA talk-list message is from 2007
It keeps the original formatting.
numero = 68870
interpreted = N
texte = Thanks Marc. To clarify, I'm trying to replicate themysql_real_escape_string() function from PHP5. I have the following grepstatement, but it won't put the backslash in front of the pattern.This: [grep search=[\'"]&replace=\\1]\'"[/grep]Should return this: \\\'\"But, I'm getting this: \\\Ideas?On 4/24/07 5:15 PM, "Marc Thompson"
wrote:> Clint,> As a rule, before writing any user entered data into a database, I> cleanse it. Here's an example:> [replace db=mydb.db&eqSKUdatarq=[cart]][formvariables> name=_&exact=F][getchars start=2][name][/getchars]=[Grep> search=[^,-.%@_A-Za-z0-9> ]&replace=][url][value][/url][/Grep]&[/formvariables][/replace]> > Here's what I use to clean up form variables passed to a page:> [formvariables]> [text][name]=[Grep search=[^,-.%@_A-Za-z0-9> ]&replace=][value][/Grep][/text]> [/formvariables]> > Notice the line wrap immediately following the 0-9. That is a space.> > HTH,> Marc> > Clint Davis wrote:> >> I need to use WebDNA to update a MySQL table. Does anyone have some words of>> advice (or code preferably) to "cleanse" the user input before executing the>> SQL UPDATE statement?-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Associated Messages, from the most recent to the oldest:
Thanks Marc. To clarify, I'm trying to replicate themysql_real_escape_string() function from PHP5. I have the following grepstatement, but it won't put the backslash in front of the pattern.This: [grep search=[\'"]&replace=\\1]\'"[/grep]Should return this: \\\'\"But, I'm getting this: \\\Ideas?On 4/24/07 5:15 PM, "Marc Thompson" wrote:> Clint,> As a rule, before writing any user entered data into a database, I> cleanse it. Here's an example:> [replace db=mydb.db&eqSKUdatarq=[cart]][formvariables> name=_&exact=F][getchars start=2][name][/getchars]=[Grep> search=[^,-.%@_A-Za-z0-9> ]&replace=][url][value][/url][/Grep]&[/formvariables][/replace]> > Here's what I use to clean up form variables passed to a page:> [formvariables]> [text][name]=[Grep search=[^,-.%@_A-Za-z0-9> ]&replace=][value][/Grep][/text]> [/formvariables]> > Notice the line wrap immediately following the 0-9. That is a space.> > HTH,> Marc> > Clint Davis wrote:> >> I need to use WebDNA to update a MySQL table. Does anyone have some words of>> advice (or code preferably) to "cleanse" the user input before executing the>> SQL UPDATE statement?-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Clint Davis
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
WebCat3.04/w*4/OS8.5.1 and aliases (1999)
Include Files (1998)
[WebDNA] Bug in [thisurlplusget] on v7 (2011)
Trouble with formula.db + more explanation (1997)
WebCatalog for Postcards ? (1997)
[WebDNA] WebDNA 8.6 announced - New features (2018)
RE: MacFinder -- a new WebDNA web site (1998)
Webcat Crashing Error 1701 (2000)
newcart (1997)
Duplicate Cart ID (2001)
Use of Back and Reload Buttons on ShoppingCart page? (1997)
WebCatalog for Postcards ? (1997)
Changing price for a SLU based on options (size, etc.) (1997)
XML - USPS Lookups - UPS Lookups (2003)
And/or Search (1998)
Small problem (2001)
international time (1997)
WebCatalog NT beta 18 problem (1997)
Locking up with WebCatalog... (1997)
Error 11 (1996)