Req #72713 [NEW]: Prepeared statements and field IN (values)
| From: | rmoisto at gmail dot com | Date: | Sat, 30 Jul 2016 14:06:47 +0000 |
| Subject: | Req #72713 [NEW]: Prepeared statements and field IN (values) | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-202730@lists.php.net to get a copy of this message | ||
From: rmoisto at gmail dot com
Operating system:
PHP version: Next Minor Version
Package: PDO MySQL
Bug Type: Feature/Change Request
Bug description:Prepeared statements and field IN (values)
Description:
------------
There seems to be no simple way of using prepared statements in queries
where "field IN (values)" is used.
Currently PDOStatement::execute doesn't handle it well if you give it an
array as a value. If it could convert that array to comma-separated
values instead, that would solve the issue. I'd like the test script
below to work when this is implemented.
It's not only a matter of convenience. SQL injection attacks happen
because of this.
I've implemented this in PHP code and it's not difficult. But it would
be much better if the language supported this. People recommend implode
and array_fill or str_repeat for generating question marks but that
approach is not only ugly but named parameters can't be used in the same
query.
I'm not the first to have this idea but I'm bringing it up because I
can't find an answer to why this is not implemented.
Test script:
---------------
<?php
$db = new \PDO('mysql:host=host;dbname=db', 'user', 'pass');
$res = $db->prepare(
'SELECT
name FROM table WHERE id IN :ids AND
foo = :bar'
);
$res->execute([
'ids' => [3, 2, 1],
'bar' => 'bar'
]);
var_dump($res->fetch());
Actual result:
--------------
Array to string conversion on line 9
--
Edit bug report at https://bugs.php.net/bug.php?id=72713&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72713&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72713&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72713&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72713&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72713&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72713&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72713&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72713&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72713&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72713&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72713&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72713&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72713&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72713&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72713&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72713&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72713&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72713&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72713&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72713&r=mysqlcfg