dongxue7306 2013-11-20 12:26
浏览 40
已采纳

Codeigniter允许插入查询中的单引号

Hello i have read that "Codeigniter update and insert function values are escaped automatically producing safer queries."

But i tried to insert the data with the single quote in my contactUs form. But i have noticed that single quote is added in my database.

Here is my code

Controller:

        $data=array('name'=>$this->input->post('name'),'EmailId'=>$this->input->post('emailid'));

        $this->mymodel->insert_data('mytable',$data);//Sending data to the model

Model

    public function insert_data($table,$data)
{
    $this->db->insert($table,$data);
    return 'success.';
}

Any suggetions???

Thanks in Advance

  • 写回答

1条回答 默认 最新

  • dst2007 2013-11-20 12:34
    关注

    Single quotes aren't an issue if they have been properly escaped beforehand or if they have been inserted into the table using a prepared statement. Stripping out such characters completely could violate data integrity.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?