Req #66495 [NEW]: fetchAllFiltered() method or alike for PDO
| From: | aniismovsa at gmail dot com | Date: | Thu, 16 Jan 2014 14:40:20 +0000 |
| Subject: | Req #66495 [NEW]: fetchAllFiltered() method or alike for PDO | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-183836@lists.php.net to get a copy of this message | ||
From: aniismovsa at gmail dot com
Operating system: any
PHP version: 5.5.8
Package: PDO Core
Bug Type: Feature/Change Request
Bug description:fetchAllFiltered() method or alike for PDO
Description:
------------
Hello. I think it would be very useful to have otput filtering built in
PDO. For example if use fetchAll() I get raw data which might have XSS
javascript inside. Then I have to filter it somehow e.g.
htmlspecialchars.
I think it would be great if such filtering could be done with method
like fetchAllFiltered(array('number','string','html');
For example if i have a table posts and it looks like id, title, body
then when calling fetchAllFiltered('number','string','html') i would
get
id sanitized as a number, title sanitized as a string or simply with
htmlspecialchars() and a body which would get sanitized as html. e.g. no
javascript inside, but all html tags present.
Currently to filter the data coming from database usually is used
filter_var or htmlspecialchars or anything else which i think is one
more step in development which could be dropped using
fetchAllFiltered().
Also i think that filtering could be added in default fetch methods of
PDO as an array argument which describes filtering of output for those
methods.
For example: fetchAll(array('number',string','html')); and we get the
filtered output.
--
Edit bug report at https://bugs.php.net/bug.php?id=66495&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=66495&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=66495&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=66495&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=66495&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=66495&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=66495&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=66495&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=66495&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=66495&r=support
Expected behavior: https://bugs.php.net/fix.php?id=66495&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=66495&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=66495&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=66495&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=66495&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=66495&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=66495&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=66495&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=66495&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=66495&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=66495&r=mysqlcfg