Index: mysql.php =================================================================== RCS file: /repository/pear/DB/DB/mysql.php,v retrieving revision 1.25 diff -u -r1.25 mysql.php --- mysql.php 18 Sep 2003 19:29:46 -0000 1.25 +++ mysql.php 13 Nov 2003 03:00:46 -0000 @@ -627,26 +627,34 @@ // {{{ quote() /** - * Quote the given string so it can be safely used within string delimiters - * in a query. - * @param $string mixed Data to be quoted - * @return mixed "NULL" string, quoted string or original data - */ + * Quote the given string so it can be safely used in a query. + * + * @param $str mixed data to be quoted + * + * @return mixed Submitted variable's type = returned value: + * + null = the string NULL + * + boolean = 1 if true or + * 0 if false. + * 1 and 0 used because MySQL maps BOOL to TINYINT(1). + * + integer or double = the unquoted number + * + other (including strings and numeric strings) = + * the data escaped according to MySQL's settings + * then encapsulated between single quotes + */ function quote($str = null) { - switch (strtolower(gettype($str))) { - case 'null': - return 'NULL'; - case 'integer': - case 'double': - return $str; - case 'string': - default: - if(function_exists('mysql_real_escape_string')) { - return "'".mysql_real_escape_string($str, $this->connection)."'"; - } else { - return "'".mysql_escape_string($str)."'"; - } + if (is_int($str) || is_double($str)) { + return $str; + } elseif (is_bool($str)) { + return $str ? 1 : 0; + } elseif (is_null($str)) { + return 'NULL'; + } else { + if(function_exists('mysql_real_escape_string')) { + return "'".mysql_real_escape_string($str, $this->connection)."'"; + } else { + return "'".mysql_escape_string($str)."'"; + } } } Index: mysql4.php =================================================================== RCS file: /repository/pear/DB/DB/mysql4.php,v retrieving revision 1.9 diff -u -r1.9 mysql4.php --- mysql4.php 18 Sep 2003 19:29:46 -0000 1.9 +++ mysql4.php 13 Nov 2003 03:00:47 -0000 @@ -614,31 +614,37 @@ } return true; } - // }}} + // }}} // {{{ quote() /** - * Quote the given string so it can be safely used within string delimiters - * in a query. - * @param $string mixed Data to be quoted - * @return mixed "NULL" string, quoted string or original data - */ + * Quote the given string so it can be safely used in a query. + * + * @param $str mixed data to be quoted + * + * @return mixed Submitted variable's type = returned value: + * + null = the string NULL + * + boolean = 1 if true or + * 0 if false. + * 1 and 0 used because MySQL maps BOOLEAN to TINYINT(1). + * + integer or double = the unquoted number + * + other (including strings and numeric strings) = + * the data escaped according to MySQL's settings + * then encapsulated between single quotes + */ function quote($str = null) { - switch (strtolower(gettype($str))) { - case 'null': - return 'NULL'; - case 'integer': - case 'double': - return $str; - case 'string': - default: - if(function_exists('mysql_real_escape_string')) { - return "'".mysql_real_escape_string($str, $this->connection)."'"; - } else { - return "'".mysql_escape_string($str)."'"; - } + if (is_int($str) || is_double($str)) { + return $str; + } elseif (is_bool($str)) { + return $str ? 1 : 0; + } else { + if(function_exists('mysql_real_escape_string')) { + return "'".mysql_real_escape_string($str, $this->connection)."'"; + } else { + return "'".mysql_escape_string($str)."'"; + } } } Index: odbc.php =================================================================== RCS file: /repository/pear/DB/DB/odbc.php,v retrieving revision 1.9 diff -u -r1.9 odbc.php --- odbc.php 18 Sep 2003 13:32:58 -0000 1.9 +++ odbc.php 13 Nov 2003 03:00:47 -0000 @@ -297,27 +297,34 @@ return $nrows; } + // }}} // {{{ quote() + /** - * Quote the given string so it can be safely used within string delimiters - * in a query. - * @param $string mixed Data to be quoted - * @return mixed "NULL" string, quoted string or original data - */ + * Quote the given string so it can be safely used in a query. + * + * @param $str mixed data to be quoted + * + * @return mixed Submitted variable's type = returned value: + * + null = the string NULL + * + boolean = the string TRUE or + * FALSE + * + integer or double = the unquoted number + * + other (including strings and numeric strings) = + * the data with single quotes escaped by preceeding + * single quotes then the whole string is encapsulated + * between single quotes + */ function quote($str = null) { - if (is_numeric($str)) { + if (is_int($str) || is_double($str)) { return $str; - } - switch (strtolower(gettype($str))) { - case 'null': - return 'NULL'; - case 'boolean': - return $str ? 'TRUE' : 'FALSE'; - case 'string': - default: - $str = str_replace("'", "''", $str); - return "'$str'"; + } elseif (is_bool($str)) { + return $str ? 'TRUE' : 'FALSE'; + } elseif (is_null($str)) { + return 'NULL'; + } else { + return "'" . str_replace("'", "''", $str) . "'"; } } Index: pgsql.php =================================================================== RCS file: /repository/pear/DB/DB/pgsql.php,v retrieving revision 1.29 diff -u -r1.29 pgsql.php --- pgsql.php 18 Sep 2003 19:29:46 -0000 1.29 +++ pgsql.php 13 Nov 2003 03:00:48 -0000 @@ -318,30 +318,38 @@ // }}} // {{{ quote() + /** - * Quote the given string so it can be safely used within string delimiters - * in a query. - * @param $string mixed Data to be quoted - * @return mixed "NULL" string, quoted string or original data - */ + * Quote the given string so it can be safely used in a query. + * + * @param $str mixed data to be quoted + * + * @return mixed Submitted variable's type = returned value: + * + null = the string NULL + * + boolean = the string TRUE or + * FALSE + * + integer or double = the unquoted number + * + other (including strings and numeric strings) = + * the data with single quotes escaped by preceeding + * single quotes, backslashes are escaped by preceeding + * backslashes, then the whole string is encapsulated + * between single quotes + */ function quote($str = null) { - switch (strtolower(gettype($str))) { - case 'null': - return 'NULL'; - case 'integer': - case 'double' : - return $str; - case 'boolean': - return $str ? 'TRUE' : 'FALSE'; - case 'string': - default: - $str = str_replace("'", "''", $str); - //PostgreSQL treats a backslash as an escape character. - $str = str_replace('\\', '\\\\', $str); - return "'$str'"; + if (is_int($str) || is_double($str)) { + return $str; + } elseif (is_bool($str)) { + return $str ? 'TRUE' : 'FALSE'; + } elseif (is_null($str)) { + return 'NULL'; + } else { + //PostgreSQL treats a backslash as an escape character. + $str = str_replace('\\', '\\\\', $str); + return "'" . str_replace("'", "''", $str) . "'"; } } + // }}} // {{{ numCols()