Bug #69362 [Ver->Csd]: PDO-pgsql fails to connect if password contains a leading single quote
| From: | mbeccati@php.net | Date: | Thu, 11 Jun 2015 22:28:22 +0000 |
| Subject: | Bug #69362 [Ver->Csd]: PDO-pgsql fails to connect if password contains a leading single quote | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193346@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69362&edit=1
ID: 69362
Updated by: mbeccati@php.net
Reported by: jon dot dufresne at gmail dot com
Summary: PDO-pgsql fails to connect if password contains a
leading single quote
-Status: Verified
+Status: Closed
Type: Bug
Package: PDO PgSQL
Operating System: Linux
PHP Version: 5.5.23
Assigned To: mbeccati
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of mbeccati
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7c0b8f872e3c15d50b1dc2d35be3674c24f82bf6
Log: Fix bug #69362 (PDO-pgsql fails to connect if password contains a leading single quote)
Previous Comments:
------------------------------------------------------------------------
[2015-04-03 00:44:22] jon dot dufresne at gmail dot com
Description:
------------
If a PostgreSQL user's password contains a leading single quote (apostrophe) PDO-pgsql is
unable to connect to the database as the user. The script fails with the message:
PHP Fatal error: Uncaught exception 'PDOException' with message 'SQLSTATE[08006] [7]
unterminated quoted string in connection info string'
Test script:
---------------
#!/bin/bash
echo "Trailing quote"
psql postgres -c "DROP DATABASE IF EXISTS testphp"
psql postgres -c "DROP ROLE IF EXISTS testphp"
psql postgres -c "CREATE ROLE testphp PASSWORD 'asdf''' LOGIN"
psql postgres -c "CREATE DATABASE testphp OWNER testphp"
php -r "new PDO(\"pgsql:dbname=testphp\", \"testphp\",
\"asdf'\");"
echo "Leading quote"
psql postgres -c "DROP DATABASE IF EXISTS testphp"
psql postgres -c "DROP ROLE IF EXISTS testphp"
psql postgres -c "CREATE ROLE testphp PASSWORD '''asdf' LOGIN"
psql postgres -c "CREATE DATABASE testphp OWNER testphp"
php -r "new PDO(\"pgsql:dbname=testphp\", \"testphp\",
\"'asdf\");"
Expected result:
----------------
PHP can connect to the database no problem.
Output from script:
$ bash test.sh
Trailing quote
DROP DATABASE
DROP ROLE
CREATE ROLE
CREATE DATABASE
Leading quote
DROP DATABASE
DROP ROLE
CREATE ROLE
CREATE DATABASE
Actual result:
--------------
$ bash test.sh
Trailing quote
DROP DATABASE
DROP ROLE
CREATE ROLE
CREATE DATABASE
Leading quote
DROP DATABASE
DROP ROLE
CREATE ROLE
CREATE DATABASE
PHP Fatal error: Uncaught exception 'PDOException' with message 'SQLSTATE[08006] [7]
unterminated quoted string in connection info string' in Command line code:1
Stack trace:
#0 Command line code(1): PDO->__construct('pgsql:dbname=te...', 'testphp',
''asdf')
#1 {main}
thrown in Command line code on line 1
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69362&edit=1