PHP字符串处理问题:&后内容丢失,需用于mysqli_query
Hey there, let's figure out why your string is getting truncated and how to fix it so you can use the & properly in your mysqli_query.
What's Causing the Truncation?
It sounds like one of two common issues is at play here:
- Browser/HTML Context Truncation: If you're echoing the string directly into HTML without proper escaping or quoting (like inside an attribute without quotes), the
&(which the browser parses to a plain&) acts as an HTML/attribute separator. This tells the browser to stop rendering content after that point, making it look like the rest of the string is missing. Even if you removehtmlspecialchars(), the raw&in the string will still trigger this issue in HTML contexts. - Accidental Parameter Parsing: If your original string came from a URL parameter or form submission (not just a hardcoded variable), the
&gets treated as a parameter separator. For example, if you passed the string via aGETrequest URL, the server would split the string at the&and only keep the part before it.
Also, using htmlspecialchars() on a string that already has & (an HTML entity) will double-escape it to &, which doesn't fix the truncation issue—it just makes the entity more nested.
Fixes to Preserve the & for mysqli_query
Here's how to get your full string back and use it safely in database queries:
1. First, Verify the Actual String Content
Stop using echo to check the string—use var_dump($mystring) instead. var_dump will show you the raw, unparsed content of the variable, so you can confirm if the full string is actually present in PHP, or if it's getting truncated before you even process it.
2. Fix HTML Output Truncation
If the issue is just how the browser renders it (but the string is intact in PHP), when echoing into HTML:
- Always wrap attributes in quotes, and use
htmlspecialchars()correctly to escape entities:
This will prevent the browser from interpreting// For text inside HTML elements echo htmlspecialchars($mystring); // For HTML attributes (add ENT_QUOTES to escape single/double quotes) echo '<div data-text="' . htmlspecialchars($mystring, ENT_QUOTES) . '"></div>';&as a separator.
3. Fix Parameter Truncation (if coming from URL/Form)
If your string is coming from a URL or form:
- For GET requests: When passing the string in a URL, use
urlencode()on the entire string to encode the&so it doesn't act as a parameter separator:
When receiving it, PHP will automatically decode it into$encodedString = urlencode("DTI ORIENTATION: CONSUMER PROTECTION & LEMON LAW"); // Use $encodedString in your URL, e.g., ?mystring=$encodedString$_GET['mystring']with the full content. - For forms: Use the
POSTmethod instead ofGET—POST data doesn't use&as a separator, so the full string will be preserved in$_POST['mystring'].
4. Prepare the String for mysqli_query
To safely use the string in a database query (and preserve the &), don't use htmlspecialchars()—that's for HTML output, not database queries. Instead:
- Use
mysqli_real_escape_string()to escape special characters that could break your query or cause SQL injection:// Assuming $conn is your mysqli connection $safeString = mysqli_real_escape_string($conn, $mystring); // Now use $safeString in your query $query = "INSERT INTO your_table (column_name) VALUES ('$safeString')"; $result = mysqli_query($conn, $query); - Even better: Use prepared statements, which are the safest way to handle database queries without manual escaping:
$stmt = mysqli_prepare($conn, "INSERT INTO your_table (column_name) VALUES (?)"); mysqli_stmt_bind_param($stmt, "s", $mystring); mysqli_stmt_execute($stmt);
内容的提问来源于stack exchange,提问作者MDB

