PDO::quote

PHP PDO 参考手册PHP PDO Reference Manual

PDO::quote — Adds quotes to a string in an SQL statement. (PHP 5 >= 5.1.0, PECL pdo >= 0.2.1)


Description

Syntax

public string PDO::quote ( string $string [, int $parameter_type = PDO::PARAM_STR ] )

PDO::quote() adds quotes to a string in an SQL statement or escapes special characters.


Parameters

string
The string to be quoted.

parameter_type
Provides a data type for the driver.


Return Values

Returns a quoted string that is theoretically safe to pass into an SQL statement and execute. Returns FALSE if the driver does not support this.


Examples

Add quotes to a normal string

<?php
$conn = new PDO('sqlite:/home/lynn/music.sql3');

/* Simple string */
$string = 'Nice';
print "Unquoted string: $string\n";
print "Quoted string: " . $conn->quote($string) . "\n";
?>

The above output is:

Unquoted string: Nice
Quoted string: 'Nice'

Escape a special string

<?php
$conn = new PDO('sqlite:/home/lynn/music.sql3');

/* Dangerous string */
$string = 'Naughty \' string';
print "Unquoted string: $string\n";
print "Quoted string:" . $conn->quote($string) . "\n";
?>

The above example will output:

Unquoted string: Naughty ' string
Quoted string: 'Naughty '' string'

PHP PDO 参考手册PHP PDO Reference Manual

Other Extensions