Req #72713 [NEW]: Prepeared statements and field IN (values)

From: Date: Sat, 30 Jul 2016 14:06:47 +0000
Subject: Req #72713 [NEW]: Prepeared statements and field IN (values)
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202730@lists.php.net to get a copy of this message
From: rmoisto at gmail dot com Operating system: PHP version: Next Minor Version Package: PDO MySQL Bug Type: Feature/Change Request Bug description:Prepeared statements and field IN (values) Description: ------------ There seems to be no simple way of using prepared statements in queries where "field IN (values)" is used. Currently PDOStatement::execute doesn't handle it well if you give it an array as a value. If it could convert that array to comma-separated values instead, that would solve the issue. I'd like the test script below to work when this is implemented. It's not only a matter of convenience. SQL injection attacks happen because of this. I've implemented this in PHP code and it's not difficult. But it would be much better if the language supported this. People recommend implode and array_fill or str_repeat for generating question marks but that approach is not only ugly but named parameters can't be used in the same query. I'm not the first to have this idea but I'm bringing it up because I can't find an answer to why this is not implemented. Test script: --------------- <?php $db = new \PDO('mysql:host=host;dbname=db', 'user', 'pass'); $res = $db->prepare( 'SELECT name FROM table WHERE id IN :ids AND foo = :bar' ); $res->execute([ 'ids' => [3, 2, 1], 'bar' => 'bar' ]); var_dump($res->fetch()); Actual result: -------------- Array to string conversion on line 9 -- Edit bug report at https://bugs.php.net/bug.php?id=72713&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72713&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72713&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72713&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=72713&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=72713&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=72713&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=72713&r=needscript Try newer version: https://bugs.php.net/fix.php?id=72713&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=72713&r=support Expected behavior: https://bugs.php.net/fix.php?id=72713&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=72713&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=72713&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=72713&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72713&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=72713&r=dst IIS Stability: https://bugs.php.net/fix.php?id=72713&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=72713&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=72713&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=72713&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=72713&r=mysqlcfg

« previous php.bugs (#202730) next »