The reason this function doesn't escape double quotes is because double quotes are used with names (the equivalent of backticks in MySQL), as in table or column names, while single quotes are used for values.
This is important to remember, especially coming from another SQL implementation. It can cause strange problems, for example, the query:
SELECT * FROM table WHERE column1="column1"
Would actually return every record, because column1 is always equal to column1. This should instead be:
SELECT * FROM table WHERE column1='column1'
Double quotes are not escaped by the function because they are not interpreted specially within single quoted strings.SQLite3::escapeString
Почист и полокален преглед на PHP референцата, со задржана структура од PHP.net и подобра читливост за примери, секции и белешки.
SQLite3::escapeString
Референца за `sqlite3.escapestring.php` со подобрена типографија и навигација.
SQLite3::escapeString
(PHP 5 >= 5.3.0, PHP 7, PHP 8)
SQLite3::escapeString — Returns a string that has been properly escaped
= NULL
Returns a string that has been properly escaped for safe inclusion in an SQL statement.
Оваа функција (сè уште) не е безбедна за бинарни податоци!
To properly handle BLOB fields which may contain NUL characters, use SQLite3Stmt::bindValue() instead.
Параметри
string-
Стрингот што треба да се избегне.
Вратени вредности
Returns a properly escaped string that may be used safely in an SQL statement.
Белешки
addslashes() should NOT be used to quote your strings for SQLite queries; it will lead to strange results when retrieving your data.