doulingqiu4349 2012-03-09 16:52
浏览 73
已采纳

需要知道这个正则表达式的作用,是否安全?

Updating someone else's old PHP project and I'm unfamiliar with regular expressions.

Question one is: What does this do?

preg_match('/^[0-9]+[.]?[0-9]*$/', $variable)

Question two is: Is this a safe filter for insertion into a mysql DB without mysql_real_escape_string()? I know the answer is prob no, but it is set up to use mysql_real_escape_string() only if this regex doesn't pass.

Thanks.

  • 写回答

7条回答 默认 最新

  • dthswrp84966 2012-03-09 16:57
    关注
    ^      // start of string
    [0-9]+ // one or more numbers (could also be \d+)
    [.]?   // zero or one period (could also be \.?)
    [0-9]* // zero or more numbers (could also be \d*)
    $      //end of string
    

    So, it makes sure the input is a number, such as 12 or 3.6 (52. will also match). It will not match .35 or 12a6.

    It seems safe enough for DB insertion, because it only allows numbers.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(6条)

报告相同问题?

悬赏问题

  • ¥15 matlab数字图像处理频率域滤波
  • ¥15 在abaqus做了二维正交切削模型,给刀具添加了超声振动条件后输出切削力为什么比普通切削增大这么多
  • ¥15 ELGamal和paillier计算效率谁快?
  • ¥15 file converter 转换格式失败 报错 Error marking filters as finished,如何解决?
  • ¥15 ubuntu系统下挂载磁盘上执行./提示权限不够
  • ¥15 Arcgis相交分析无法绘制一个或多个图形
  • ¥15 关于#r语言#的问题:差异分析前数据准备,报错Error in data[, sampleName1] : subscript out of bounds请问怎么解决呀以下是全部代码:
  • ¥15 seatunnel-web使用SQL组件时候后台报错,无法找到表格
  • ¥15 fpga自动售货机数码管(相关搜索:数字时钟)
  • ¥15 用前端向数据库插入数据,通过debug发现数据能走到后端,但是放行之后就会提示错误