Req #69348 [Opn->Nab]: mysql_real_escape_string produces invalid decimal numbers on some locales
| From: | stas@php.net | Date: | Wed, 01 Apr 2015 18:50:08 +0000 |
| Subject: | Req #69348 [Opn->Nab]: mysql_real_escape_string produces invalid decimal numbers on some locales | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-191770@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69348&edit=1
ID: 69348
Updated by: stas@php.net
Reported by: mdrolc at gmail dot com
Summary: mysql_real_escape_string produces invalid decimal
numbers on some locales
-Status: Open
+Status: Not a bug
Type: Feature/Change Request
Package: MySQL related
Operating System: All
PHP Version: 5.6.7
Block user comment: N
Private report: N
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
Doesn't look like a mysql bug. See:
setlocale(LC_ALL, 'sl_SI.UTF8');
var_dump((string)19.9);
It's just how string conversion of floats works.
Previous Comments:
------------------------------------------------------------------------
[2015-04-01 14:19:53] mdrolc at gmail dot com
Description:
------------
SQL only accepts floats with dot as the decimal separator. But running a float through
mysql_real_escape_string() returns a string with comma as the decimal separator on some locale
configurations. MySQL fails silently and just cuts off the decimal part.
This behaviour can result in nasty hard to catch bugs because behaviour depends highly on server
configuration.
mysql_real_escape_string() should always cast types according to MySQL conventions which in this
case means that decimal numbers should use dot as a decimal separator regardless of the locale
setting.
Test script:
---------------
mysql_connect("localhost", "root", "dev");
//English, everything is fine
setlocale(LC_ALL, 'en_US.UTF8');
var_dump(localeconv()['decimal_point']); //string(1) "."
var_dump(mysql_real_escape_string(19.9)); //string(4) "19.9"
//Slovene, (Use a locale that is installed on your system to successfully reproduce this)
setlocale(LC_ALL, 'sl_SI.UTF8');
var_dump(localeconv()['decimal_point']); //string(1) ","
var_dump(mysql_real_escape_string(19.9)); //string(4) "19,9"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69348&edit=1