You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP字符串处理问题:&后内容丢失,需用于mysqli_query

Hey there, let's figure out why your string is getting truncated and how to fix it so you can use the & properly in your mysqli_query.

What's Causing the Truncation?

It sounds like one of two common issues is at play here:

  1. Browser/HTML Context Truncation: If you're echoing the string directly into HTML without proper escaping or quoting (like inside an attribute without quotes), the & (which the browser parses to a plain &) acts as an HTML/attribute separator. This tells the browser to stop rendering content after that point, making it look like the rest of the string is missing. Even if you remove htmlspecialchars(), the raw & in the string will still trigger this issue in HTML contexts.
  2. Accidental Parameter Parsing: If your original string came from a URL parameter or form submission (not just a hardcoded variable), the & gets treated as a parameter separator. For example, if you passed the string via a GET request URL, the server would split the string at the & and only keep the part before it.

Also, using htmlspecialchars() on a string that already has & (an HTML entity) will double-escape it to &, which doesn't fix the truncation issue—it just makes the entity more nested.

Fixes to Preserve the & for mysqli_query

Here's how to get your full string back and use it safely in database queries:

1. First, Verify the Actual String Content

Stop using echo to check the string—use var_dump($mystring) instead. var_dump will show you the raw, unparsed content of the variable, so you can confirm if the full string is actually present in PHP, or if it's getting truncated before you even process it.

2. Fix HTML Output Truncation

If the issue is just how the browser renders it (but the string is intact in PHP), when echoing into HTML:

  • Always wrap attributes in quotes, and use htmlspecialchars() correctly to escape entities:
    // For text inside HTML elements
    echo htmlspecialchars($mystring);
    
    // For HTML attributes (add ENT_QUOTES to escape single/double quotes)
    echo '<div data-text="' . htmlspecialchars($mystring, ENT_QUOTES) . '"></div>';
    
    This will prevent the browser from interpreting & as a separator.

3. Fix Parameter Truncation (if coming from URL/Form)

If your string is coming from a URL or form:

  • For GET requests: When passing the string in a URL, use urlencode() on the entire string to encode the & so it doesn't act as a parameter separator:
    $encodedString = urlencode("DTI ORIENTATION: CONSUMER PROTECTION &amp; LEMON LAW");
    // Use $encodedString in your URL, e.g., ?mystring=$encodedString
    
    When receiving it, PHP will automatically decode it into $_GET['mystring'] with the full content.
  • For forms: Use the POST method instead of GET—POST data doesn't use & as a separator, so the full string will be preserved in $_POST['mystring'].

4. Prepare the String for mysqli_query

To safely use the string in a database query (and preserve the &), don't use htmlspecialchars()—that's for HTML output, not database queries. Instead:

  • Use mysqli_real_escape_string() to escape special characters that could break your query or cause SQL injection:
    // Assuming $conn is your mysqli connection
    $safeString = mysqli_real_escape_string($conn, $mystring);
    // Now use $safeString in your query
    $query = "INSERT INTO your_table (column_name) VALUES ('$safeString')";
    $result = mysqli_query($conn, $query);
    
  • Even better: Use prepared statements, which are the safest way to handle database queries without manual escaping:
    $stmt = mysqli_prepare($conn, "INSERT INTO your_table (column_name) VALUES (?)");
    mysqli_stmt_bind_param($stmt, "s", $mystring);
    mysqli_stmt_execute($stmt);
    

内容的提问来源于stack exchange,提问作者MDB

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:49:53