Req #76647 [NEW]: PDO's query parser should warn with multiple named parameters
| From: | requinix@php.net | Date: | Thu, 19 Jul 2018 15:11:11 +0000 |
| Subject: | Req #76647 [NEW]: PDO's query parser should warn with multiple named parameters | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-216373@lists.php.net to get a copy of this message | ||
From: requinix
Operating system:
PHP version: 7.3.0alpha4
Package: PDO Core
Bug Type: Feature/Change Request
Bug description:PDO's query parser should warn with multiple named parameters
Description:
------------
From bug #76639.
If PDO is not emulating prepares and a query contains named parameters,
SELECT a FROM b WHERE c = :param OR d = :param
it will get rewritten to use placeholders
SELECT a FROM b WHERE c = ? OR d = ?
When the user executes the query they will only provide one value, and
that results in an error because the query requires two values.
MySQL/pdo_mysql gives "SQLSTATE[HY093]: Invalid parameter number", which
is technically correct but only understandable if the user knows about
the rewriting. It also happens during the call to execute(), which is
misleading as the problem was actually in the prepared statement given
to prepare().
The docs for PDO::prepare() do speak of this:
> You cannot use a named parameter marker of the same name more than
once in a prepared statement, unless
> emulation mode is on.
The request: Since PDO is parsing and rewriting queries during
prepare(), it can recognize this situation happening and so should
present a meaningful error message/exception at that time.
Test script:
---------------
<?php
$pdo = new PDO(...);
$pdo->setAttribute(PDO::ATTR_EMULATE_PREPARES, false);
$pdo->prepare("SELECT :param, :param");
?>
Expected result:
----------------
Some appropriate error message or PDOException during $pdo->prepare().
Actual result:
--------------
Query is accepted and prepared even though it can't be executed.
--
Edit bug report at https://bugs.php.net/bug.php?id=76647&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76647&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76647&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76647&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=76647&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=76647&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=76647&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=76647&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=76647&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=76647&r=support
Expected behavior: https://bugs.php.net/fix.php?id=76647&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=76647&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=76647&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=76647&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76647&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=76647&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=76647&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=76647&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=76647&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=76647&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=76647&r=mysqlcfg