@@ -162,14 +162,8 @@ private function getWhereClause(
162162 // (like INT), for a LIKE we always quote the value. MySQL converts
163163 // strings to numbers and numbers to strings as necessary
164164 // during the comparison
165- if (
166- preg_match ('@char|binary|blob|text|set|date|time|year|uuid@i ' , $ types )
167- || mb_strpos (' ' . $ funcType , 'LIKE ' )
168- ) {
169- $ quot = '\'' ;
170- } else {
171- $ quot = '' ;
172- }
165+ $ needsQuoting = preg_match ('@char|binary|blob|text|set|date|time|year|uuid@i ' , $ types )
166+ || mb_strpos (' ' . $ funcType , 'LIKE ' );
173167
174168 // LIKE %...%
175169 if ($ funcType === 'LIKE %...% ' ) {
@@ -193,8 +187,8 @@ private function getWhereClause(
193187 && $ funcType !== 'BETWEEN '
194188 && $ funcType !== 'NOT BETWEEN '
195189 ) {
196- return $ backquotedName . ' ' . $ funcType . ' ' . $ quot
197- . $ this ->dbi ->escapeString ($ criteriaValues ) . $ quot ;
190+ return $ backquotedName . ' ' . $ funcType . ' '
191+ . ( $ needsQuoting ? $ this ->dbi ->quoteString ($ criteriaValues ) : $ criteriaValues ) ;
198192 }
199193
200194 $ funcType = str_replace (' (...) ' , '' , $ funcType );
@@ -209,15 +203,18 @@ private function getWhereClause(
209203
210204 // quote values one by one
211205 $ emptyKey = false ;
212- foreach ($ values as $ key => & $ value ) {
206+ foreach ($ values as $ key => $ value ) {
213207 if ($ value === '' ) {
214208 $ emptyKey = $ key ;
215- $ value = 'NULL ' ;
209+ $ values [$ key ] = 'NULL ' ;
210+ continue ;
211+ }
212+
213+ if (! $ needsQuoting ) {
216214 continue ;
217215 }
218216
219- $ value = $ quot . $ this ->dbi ->escapeString (trim ($ value ))
220- . $ quot ;
217+ $ values [$ key ] = $ this ->dbi ->quoteString (trim ($ value ));
221218 }
222219
223220 if ($ funcType === 'BETWEEN ' || $ funcType === 'NOT BETWEEN ' ) {
@@ -334,11 +331,9 @@ private function getEnumWhereClause(mixed $criteriaValues, string $funcType): st
334331 $ parensClose = '' ;
335332 }
336333
337- $ enumWhere = '\''
338- . $ this ->dbi ->escapeString ($ criteriaValues [0 ]) . '\'' ;
334+ $ enumWhere = $ this ->dbi ->quoteString ($ criteriaValues [0 ]);
339335 for ($ e = 1 ; $ e < $ enumSelectedCount ; $ e ++) {
340- $ enumWhere .= ', \''
341- . $ this ->dbi ->escapeString ($ criteriaValues [$ e ]) . '\'' ;
336+ $ enumWhere .= ', ' . $ this ->dbi ->quoteString ($ criteriaValues [$ e ]);
342337 }
343338
344339 return ' ' . $ funcType . ' ' . $ parensOpen
0 commit comments