3 ms·
I don't have a problem with this. If I am trying to figure out how to do something, I'd rather the help be focused on the thing, and not confuse my by adding th
by paul_f 5y ago
I don't have a problem with this. If I am trying to figure out how to do something, I'd rather the help be focused on the thing, and not confuse my by adding the mysqli_real_escape_string stuff. Yes, I know about little bobby tables and all that. Same with trying to see an example of a php form. I don't need the csrftoken, I already know to do that. Yes, it might help a novice, but don't make everything more complicated just for beginners benefit
- TeMPOraL 5y ago> If I am trying to figure out how to do something, I'd rather the help be focused on the thing, and not confuse my by adding the mysqli_real_escape_string stuff. In this case, the help is fundamentally wrong. Other than "what is an example of a dumb programming mistake?", there aren't really questions to which a valid answer involves concatenating arbitrary strings and executing the result as an SQL command. If your question is, "how do I execute an SQL command?", there are many better examples to use. If the question is, "how do I store user-supplied data in the database?", or "how do I query using user-supplied values", then the answer should not give you what amounts to an accidentally working hack. SQL is a language of its own. It has a syntax and a grammar. When generating SQL from PHP (or any other language), you're switching languages - there must be a translation step involved. Any answer that doesn't bring this up explicitly is just wrong.
- mgkimsal 5y ago> "... and not confuse my by adding the mysqli_real_escape_string stuff... CSRF token ...I already know to do that..." If you're already that good, how does seeing a CSRF token in an answer actually impact you? Does it prevent you from copy/pasting someone's "example" code?