#48290 [Opn->Bgs]: auto escape for variables in double quoted sql string
| From: | derick@php.net | Date: | Wed, 16 Dec 2009 10:41:10 +0000 |
| Subject: | #48290 [Opn->Bgs]: auto escape for variables in double quoted sql string | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-145785@lists.php.net to get a copy of this message | ||
ID: 48290
Updated by: derick@php.net
Reported By: kexianbin at diyism dot com
-Status: Open
+Status: Bogus
Bug Type: Feature/Change Request
Operating System: Irrelevant
PHP Version: 5.3.2
New Comment:
.
Previous Comments:
------------------------------------------------------------------------
[2009-12-16 08:52:56] kexianbin at diyism dot com
I think to realize auto escape for double quoted strings is easier than
to inherit variables from parent scope.
------------------------------------------------------------------------
[2009-11-27 01:53:32] kexianbin at diyism dot com
Rasmus,
Another way,
similar to reserved word 'global' to inherit variables from global
scope, why can't we add a reserved word 'inherit' to inherit varialbes
from parent scope?
I think it's very useful since it's a great advantage now aday in
javascript communities.
Malcolm
------------------------------------------------------------------------
[2009-11-19 07:12:38] rasmus@php.net
We did get rid of it.
------------------------------------------------------------------------
[2009-11-19 07:12:06] kexianbin at diyism dot com
For matching preciseness,
we could only support the format: "...{#BatchId}...",
not to support this format: "...#BatchId...".
------------------------------------------------------------------------
[2009-11-19 07:07:51] kexianbin at diyism dot com
Rasmus,
We really should to get rid of sql string auto escape in data of POST,
GET, COOKIE etc,
instead, we put off the sql string auto escape right before the sql
string to be executed.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/48290
--
Edit this bug report at http://bugs.php.net/?id=48290&edit=1