Thread: best way yo Store And Display CODE BLOCK?

    best way yo Store And Display CODE BLOCK?

    i am developing a Search Engine by PHP, which search any Code Block i have posts and store, like MSDN
    and My website will store ALL type PROGRAMMING LANGUAGES ( PHP, c#, JS...) ( Estimates about 10.000 Code )

    And bestway to implement that? how to Avoid SQL Injection if I store my Code block in Database.
    if dont choose Database to Store, what is another way to do???


    You would prevent SQL injection the same way you would with any other text inputs: either via prepared statements and bound parameters (e.g. if using the PDO or MySQLi DB extension) or by using the applicable escaping function for your DB extension (e.g. mysql_real_escape_string() if using the now-deprecated MySQL extension).

    When outputting it to the browser (probably within <pre> tags), use htmlentities() on that text so that it does not mess up your HTML, also preventing any JavaScript injection as a bonus. (If it's PHP code, you can use highlight_string() instead, which will add colored syntax highlighting as well.)
