Problem Solution Discussion Including Special Characters and NULL Values in Queries
2.8 Including Special Characters and NULL Values in Queries
2.8.1 Problem
Youve having t rouble const ruct ing queries t hat include dat a values cont aining special charact ers such as quot es or backslashes, or special values such as NULL .2.8.2 Solution
Use your API s placeholder m echanism or quot ing funct ion.2.8.3 Discussion
Up t o t his point , our queries have used safe dat a values requiring no special t reat m ent . This sect ion describes how t o const ruct queries when youre using values t hat cont ain special charact ers such as quot es, backslashes, binary dat a, or values t hat ar e NULL . The difficult y wit h such values is as follows. Suppose you have t he following INSERT query: INSERT INTO profile name,birth,color,foods,cats VALUESAlison,1973-01-12,blue,eggroll,4; Theres not hing unusual about t hat . But if you change t he name colum n value t o som et hing like DeMont t hat cont ains a single quot e, t he query becom es synt act ically invalid: INSERT INTO profile name,birth,color,foods,cats VALUESDeMont,1973-01-12,blue,eggroll,4; The problem is t hat t here is a single quot e inside a single-quot ed st ring. To m ake t he query legal, t he quot e could be escaped by preceding it eit her wit h a single quot e or wit h a backslash: INSERT INTO profile name,birth,color,foods,cats VALUESDeMont,1973-01-12,blue,eggroll,4; INSERT INTO profile name,birth,color,foods,cats VALUESDe\Mont,1973-01-12,blue,eggroll,4; Alt ernat ively, you could quot e t he name value it self wit hin double quot es rat her t han wit hin single quot es: INSERT INTO profile name,birth,color,foods,cats VALUESDeMont,1973-01-12,blue,eggroll,4; Nat urally, if you are writ ing a query lit erally in your program , you can escape or quot e t he name value by hand because you know what t he value is. But if youre using a variable t o provide t he name value, you dont necessarily know what t he variables value is. Worse yet , single quot e isnt t he only charact er you m ust be prepared t o deal wit h; double quot es and backslashes cause problem s, t oo. And if you want t o st ore binary dat a such as im ages or sound clips in your dat abase, such values m ight cont ain anyt hing—not j ust quot es or backslashes, but ot her charact ers such as nulls zero-valued byt es . The need t o handle special charact ers properly is part icularly acut e in a web environm ent where queries are const ruct ed using form input for exam ple, if youre searching for records t hat m at ch search t erm s ent ered by t he rem ot e user . You m ust be able t o handle any kind of input in a general way, because you cant predict in advance what kind of inform at ion people will supply. I n fact , it is not uncom m on for m alicious users t o ent er garbage values cont aining problem at ic charact ers in a deliberat e at t em pt t o break your script s. The SQL NULL value is not a special charact er, but it t oo requires special t reat m ent . I n SQL, NULL indicat es no value. This can have several m eanings depending on cont ext , such as unknown, m issing, out of range, and so fort h. Our queries t hus far have not used NULL values, t o avoid dealing wit h t he com plicat ions t hat t hey int roduce, but now it s t im e t o address t hese issues. For exam ple, if you dont know DeMont s favorit e color, you can set t he color colum n t o NULL —but not by writ ing t he query like t his: INSERT INTO profile name,birth,color,foods,cats VALUESDeMont,1973-01-12,NULL,eggroll,4; I nst ead, t he NULL value shouldnt have any surrounding quot es at all: INSERT INTO profile name,birth,color,foods,cats VALUESDeMont,1973-01-12,NULL,eggroll,4; I f you were writ ing t he query lit erally in your program , youd sim ply writ e t he word NULL wit hout surrounding quot es. But if t he color value com es from a variable, t he proper act ion is not so obvious. You m ust know som et hing about t he variables value t o be able t o det erm ine whet her or not t o surround it wit h quot es when you const ruct t he query. There are t wo general m eans at your disposal for dealing wit h special charact ers such as quot es and backslashes, and wit h special values such as NULL : • Use placeholders if your API support s t hem . Generally, t his is t he preferred m et hod, because t he API it self will do all or m ost of t he work for you of providing quot es around values as necessary, quot ing or escaping special charact ers wit hin t he dat a value, and possibly int erpret ing a special value t o m ap ont o NULL wit hout surrounding quot es. Recipe 2.7 provides general background on placeholder support ; you should read t hat sect ion if you havent already. • Use a quot ing funct ion if your API provides one for convert ing dat a values t o a safe form t hat is suit able for use in query st rings. The rem ainder of t his sect ion shows how t o handle special charact ers for each API . The exam ples dem onst rat e how t o insert a profile t able record t hat cont ains DeMont for t he name value and NULL for t he color value. The t echniques shown work generally t o handle any special charact ers, including t hose found in binary dat a. The t echniques are not lim it ed t o INSERT queries. They work for ot her kinds of st at em ent s as well, such as SELECT queries. Exam ples showing specifically how t o work wit h a part icular kind of binary dat a—im ages—are provided in Chapt er 17 . A relat ed issue not covered here is t he inverse operat ion of t ransform ing special charact ers in values ret urned from your dat abase for display in various cont ext s. For exam ple, if youre generat ing HTML pages t hat include values t aken from your dat abase, you have t o convert and charact ers in t hose values t o t he HTML ent it ies lt; and gt; t o m ake sure t hey display properly. This t opic is discussed in Chapt er 16 .2.8.4 Perl
Parts
» O'Reilly-MySQL.Cookbook.eBook-iNTENSiTY. 4810KB Mar 29 2010 05:03:43 AM
» Introduction Using the mysql Client Program
» Problem Solution Discussion Setting Up a MySQL User Account
» Problem Solution Discussion Starting and Terminating mysql
» Problem Solution Discussion Specifying Connection Parameters by Using Option Files
» Problem Solution Discussion Mixing Command-Line and Option File Parameters
» Problem Solution Discussion What to Do if mysql Cannot Be Found
» Problem Solution Discussion Setting Environment Variables
» Problem Solution Discussion Repeating and Editing Queries
» Problem Solution Discussion Preventing Query Output from Scrolling off the Screen
» Problem Solution Discussion Specifying Arbitrary Output Column Delimiters
» Problem Solution Discussion Logging Interactive mysql Sessions
» Discussion Using mysql as a Calculator
» Writing Shell Scripts Under Unix
» Writing Shell Scripts Under Windows
» MySQL Client Application Programming Interfaces
» Perl Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» PHP Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Python Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Java Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Problem Solution Discussion Checking for Errors
» Python Java Checking for Errors
» Problem Solution Discussion Writing Library Files
» Python Writing Library Files
» SQL Statement Categories Issuing Queries and Retrieving Results
» Perl Issuing Queries and Retrieving Results
» Python Issuing Queries and Retrieving Results
» Java Issuing Queries and Retrieving Results
» Problem Solution Discussion Moving Around Within a Result Set
» Problem Solution Discussion Using Prepared Statements and Placeholders in Queries
» Perl Using Prepared Statements and Placeholders in Queries
» PHP Python Java Using Prepared Statements and Placeholders in Queries
» Problem Solution Discussion Including Special Characters and NULL Values in Queries
» Perl Including Special Characters and NULL Values in Queries
» PHP Including Special Characters and NULL Values in Queries
» Python Java Including Special Characters and NULL Values in Queries
» PHP Python Java Handling NULL Values in Result Sets
» Problem Solution Discussion Writing an Object-Oriented MySQL Interface for PHP
» Class Overview Writing an Object-Oriented MySQL Interface for PHP
» Connecting and Disconnecting Writing an Object-Oriented MySQL Interface for PHP
» Error Handling Issuing Queries and Processing the Results
» Quoting and Placeholder Support
» Problem Solution Discussion Ways of Obtaining Connection Parameters
» Getting Parameters from the Command Line
» Getting Parameters from Option Files
» Conclusion and Words of Advice
» Problem Solution Discussion Avoiding Output Column Order Problems When Writing Programs
» Problem Solution Discussion Using Column Aliases to Make Programs Easier to Write
» Problem Solution Discussion Selecting a Result Set into an Existing Table
» Problem Solution Discussion Creating a Destination Table on the Fly from a Result Set
» Problem Solution Discussion Moving Records Between Tables Safely
» Problem Solution Discussion Cloning a Table Exactly
» Problem Solution Discussion Generating Unique Table Names
» Problem Solution Discussion Using TIMESTAMP Values
» Problem Solution Discussion Using ORDER BY to Sort Query Results
» Solution Discussion Working with Per-Group and Overall Summary Values Simultaneously
» Problem Solution Discussion Changing a Column Definition or Name
» Problem Solution Discussion Changing a Table Type
» Problem Solution Discussion Adding Indexes
» Introduction Obtaining and Using Metadata
» Problem Solution Discussion Perl PHP
» Problem Solution Discussion Perl
» PHP Obtaining Result Set Metadata
» Python Obtaining Result Set Metadata
» Java Obtaining Result Set Metadata
» Using Result Set Metadata to Get Table Structure
» Problem Solution Discussion Database-Independent Methods of Obtaining Table Information
» Problem Solution Discussion Displaying Column Lists Interactive Record Editing
» Mapping Column Types onto Web Page Elements Adding Elements to ENUM or SET Column Definitions
» Selecting All Except Certain Columns
» Problem Solution Discussion Listing Tables and Databases
» Problem Solution Writing Applications That Adapt to the MySQL Server Version
» Discussion Writing Applications That Adapt to the MySQL Server Version
» Problem Solution Discussion Determining Which Table Types the Server Supports
» General Import and Export Issues
» Problem Solution Discussion Importing Data with LOAD DATA and mysqlimport
» Problem Solution Discussion Specifying the Datafile Location
» Problem Solution Discussion Specifying the Datafile Format
» Problem Solution Discussion Dealing with Quotes and Special Characters
» Problem Solution Discussion Handling Duplicate Index Values
» Problem Solution Discussion Getting LOAD DATA to Cough Up More Information
» Problem Solution Discussion Dont Assume LOAD DATA Knows More than It Does
» Problem Solution Discussion Skipping Datafile Columns
» Problem Solution Discussion Exporting Query Results from MySQL
» Using the mysql Client to Export Data
» Problem Solution Discussion Exporting Tables as Raw Data
» Problem Solution Discussion Exporting Table Contents or Definitions in SQL Format
» Problem Solution Discussion Copying Tables or Databases to Another Server
» Problem Solution Discussion Writing Your Own Export Programs
» Problem Solution Discussion Converting Datafiles from One Format to Another
» Problem Solution Discussion Extracting and Rearranging Datafile Columns
» Problem Solution Discussion Validating and Transforming Data
» Writing an Input-Processing Loop Putting Common Tests in Libraries
» Problem Solution Discussion Validation by Pattern Matching
» Problem Solution Discussion Using Patterns to Match Numeric Values
» Problem Solution Discussion Using Patterns to Match Dates or Times
» See Also Using Patterns to Match Dates or Times
» Problem Solution Discussion Using Patterns to Match Email Addresses and URLs
» Problem Solution Discussion Validation Using Table Metadata
» Problem Solution Discussion Issue Individual Queries Construct a Hash from the Entire Lookup Table
» Use a Hash as a Cache of Already-Seen Lookup Values
» Problem Solution Discussion Converting Two-Digit Year Values to Four-Digit Form
» Problem Solution Discussion Performing Validity Checking on Date or Time Subparts
» Problem Solution Discussion Writing Date-Processing Utilities
» Problem Solution Discussion Performing Date Conversion Using SQL
» Problem Solution Discussion Guessing Table Structure from a Datafile
» Problem Solution Discussion A LOAD DATA Diagnostic Utility
» Problem Solution Discussion Exchanging Data Between MySQL and Microsoft Access
» Problem Solution Discussion Exchanging Data Between MySQL and Microsoft Excel
» Problem Solution Discussion Exchanging Data Between MySQL and FileMaker Pro
» Problem Solution Discussion Importing XML into MySQL
» Epilog Importing and Exporting Data
» Introduction Generating and Using Sequences
» Problem Solution Discussion Using AUTO_INCREMENT To Set Up a Sequence Column
» Problem Solution Discussion Choosing the Type for a Sequence Column
» Problem Solution Discussion Ensuring That Rows Are Renumbered in a Particular Order
» Problem Solution Discussion Managing Multiple Simultaneous AUTO_INCREMENT Values
» Problem Solution Discussion Using AUTO_INCREMENT Values to Relate Tables
» Problem Solution Discussion Generating Repeating Sequences
» Problem Solution Discussion See Also
» Performing a Related-Table Update Using Table Replacement
» Performing a Related-Table Update by Writing a Program
» Performing a Multiple-Table Delete by Writing a Program
» Problem Solution Discussion Dealing with Duplicates at Record-Creation Time
» Problem Solution Discussion Using Transactions in Perl Programs
» Problem Solution Discussion Using Transactions in Java Programs
» Problem Solution Discussion Using Alternatives to Transactions
» Grouping Statements Using Locks
» Rewriting Queries to Avoid Transactions
» Introduction Introduction to MySQL on the Web
» Problem Solution Discussion Basic Web Page Generation
» Problem Solution Discussion Using Apache to Run Web Scripts
» Problem Solution Discussion Using Tomcat to Run Web Scripts
» Installing the mcb Application
» Installing the JSTL Distribution
» Problem Solution Discussion Encoding Special Characters in Web Output
» General Encoding Principles Encoding Special Characters in Web Output
» Encoding Special Characters Using Web APIs
» Introduction Incorporating Query Results into Web Pages
» Problem Solution Discussion Creating a Navigation Index from Database Content
» Creating a Multiple-Page Navigation Index
» Problem Solution Discussion Storing Images or Other Binary Data
» Storing Images with LOAD_FILE Storing Images Using a Script
» Problem Solution Discussion Retrieving Images or Other Binary Data
» Problem Solution Discussion Serving Banner Ads
» Problem Solution Discussion Serving Query Results for Download
» Introduction Processing Web Input with MySQL
» Problem Solution Discussion Creating Forms in Scripts
» Problem Solution Discussion Creating Multiple-Pick Form Elements from Database Content
» Problem Solution Discussion Loading a Database Record into a Form
» Problem Solution Discussion Collecting Web Input
» Web Input Extraction Conventions Perl
» Problem Solution Discussion Validating Web Input
» Problem Solution Discussion Using Web Input to Construct Queries
» Problem Solution Discussion Processing File Uploads
» Perl Processing File Uploads
» Problem Solution Discussion Performing Searches and Presenting the Results
» Problem Solution Discussion Generating Previous-Page and Next-Page Links
» Paged Displays with Previous-Page and Next-Page Links
» Paged Displays with Links to Each Page
» Problem Solution Discussion Web Page Access Counting
» Problem Solution Discussion Web Page Access Logging
» Problem Solution Discussion Setting Up Database Logging
» Other Logging Issues Using MySQL for Apache Logging
» Session Management Issues Introduction
» Problem Solution Discussion Installing Apache::Session
» The Apache::Session Interface
» A Sample Application Using MySQL-Based Sessions in Perl Applications
» Problem Solution Discussion The PHP 4 Session Management Interface
» Specifying a User-Defined Storage Module
» Problem Solution Discussion Using MySQL for Session BackingStore with Tomcat
» The Servlet and JSP Session Interface A Sample JSP Session Application
Show more