Bug #44639 [Opn->Csd]: PDO quotes integers in prepared statement

From: Date: Mon, 10 Oct 2016 22:27:21 +0000
Subject: Bug #44639 [Opn->Csd]: PDO quotes integers in prepared statement
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204585@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=44639&edit=1

 ID:                 44639
 Updated by:         adambaratz@php.net
 Reported by:        jgauld at blueyonder dot co dot uk
 Summary:            PDO quotes integers in prepared statement
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            PDO Core
 Operating System:   *
 PHP Version:        5.*
-Assigned To:        
+Assigned To:        adambaratz
 Block user comment: N
 Private report:     N

 New Comment:

I had a duplicate ticket in for this issue (#73234). The fix I committed references the newer
ticket.


Previous Comments:
------------------------------------------------------------------------
[2015-07-23 21:58:17] chealer at gmail dot com

sjoerd@php.net, what makes you claim that "The third parameter to bindValue defaults to
PDO::PARAM_STR."?

See related ticket #49614 (regarding PDOStatement::execute's second argument).

------------------------------------------------------------------------
[2015-06-17 02:42:58] shankao at gmail dot com

Indeed, the problem seems to happen only with emulated prepares.

The code that checks how the type needs to be emulated [1] is not using the PDO_PARAM_* hint at all.
It tries to guess the type by itself and uses convert_to_string() on each type but NULL's and
BOOL's [2]

[1] pdo_parse_params()
[2] See current git PHP code file ext/pdo/pdo_sql_parser.c around line 894

------------------------------------------------------------------------
[2014-01-26 18:12:50] mightyuhu@php.net

Confirmed on php 5.3.10-1ubuntu3.8 and MySQL 5.5.32

------------------------------------------------------------------------
[2012-12-05 04:02:03] alek0585 at mail dot ru

Yeah! Try this $db->setAttribute(PDO::ATTR_EMULATE_PREPARES, false); and you can 
use that!
foreach($data as $key => $value) {
            $stmt->bindParam( ":".$key, $value, (is_int($value) ? PDO::PARAM_INT : 
PDO::PARAM_STR));
        }
but you should be careful with types of vars

------------------------------------------------------------------------
[2012-03-12 10:15:44] alvaro at demogracia dot com

This only happens on emulated parameter binding, i.e. when PDO::ATTR_EMULATE_PREPARES is TRUE.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=44639


--
Edit this bug report at https://bugs.php.net/bug.php?id=44639&edit=1


Thread (25 messages)

« previous php.bugs (#204585) next »