Req #64810 [Com]: impossible to load extension via pdo_sqlite
Edit report at https://bugs.php.net/bug.php?id=64810&edit=1
ID: 64810
Comment by: bugs dot php dot net at businger dot ch
Reported by: kamatoz at gmail dot com
Summary: impossible to load extension via pdo_sqlite
Status: Open
Type: Feature/Change Request
Package: PDO related
Operating System: any
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
+1: please make this a php.ini option
Previous Comments:
------------------------------------------------------------------------
[2014-09-17 14:55:57] benjamin dot morel at gmail dot com
+1
Definitely a show-stopper!
------------------------------------------------------------------------
[2013-10-23 18:14:31] jwhite at tdc-group dot com
Very much need this too. Would it be possible, if this is disabled for security concerns, to offer
a flag in the php.ini to enable this feature?
I'm not sure how helpful this is, but someone has hacked their own copy of php to allow the
load_extension function to work with PDO.
http://stackoverflow.com/questions/8756146/how-to-load-sqlite-extension-in-pdo
--- php-5.3.7.old/ext/pdo_sqlite/sqlite_driver.c 2012-01-06 11:04:44.000000000 -0500
+++ sqlite_driver.c 2012-01-06 08:16:58.000000000 -0500
@@ -718,6 +718,8 @@
goto cleanup;
}
+ sqlite3_enable_load_extension(H->db, 1);
+
if (PG(safe_mode) || (PG(open_basedir) && *PG(open_basedir))) {
sqlite3_set_authorizer(H->db, authorizer, NULL);
}
------------------------------------------------------------------------
[2013-05-10 07:38:31] kamatoz at gmail dot com
Description:
------------
Currently if you use php pdo_sqlite it's impossible to load an sqlite extension
to sqlite. It's good practice to turn off this opportunity by default, but it
should be possible to override the behavior via config file
Test script:
---------------
$pdo = new PDO('sqlite:test.db','','',[PDO::ATTR_ERRMODE=>
PDO::ERRMODE_EXCEPTION]);
try {
$result = $pdo->query('select load_extension("libspatialite.so.3")');
}
catch (PDOException $e) {
echo "Failed to get DB handle: " . $e->getMessage() . "\n";
exit;
}
Expected result:
----------------
No exception should be thrown
Actual result:
--------------
Failed to get DB handle: SQLSTATE[HY000]: General error: 1 not authorized
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=64810&edit=1
Thread (8 messages)