Req #66495 [Opn->Wfx]: fetchAllFiltered() method or alike for PDO
| From: | peehaa@php.net | Date: | Wed, 15 May 2019 20:34:06 +0000 |
| Subject: | Req #66495 [Opn->Wfx]: fetchAllFiltered() method or alike for PDO | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220861@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66495&edit=1
ID: 66495
Updated by: peehaa@php.net
Reported by: aniismovsa at gmail dot com
Summary: fetchAllFiltered() method or alike for PDO
-Status: Open
+Status: Wont fix
Type: Feature/Change Request
Package: PDO related
Operating System: any
PHP Version: 5.5.8
Block user comment: N
Private report: N
New Comment:
Handling data in a way to prevent specific kinds of attacks should be done at the place where it is
used. For the specific kinds of attacks you mentioned it makes no sense for the database layer to
try (and fail to) handle this.
Previous Comments:
------------------------------------------------------------------------
[2014-03-06 14:39:40] narf at devilix dot net
-1 ... or rather -2
XSS (or any kind of output filtering) isn't PDO's job.
------------------------------------------------------------------------
[2014-01-16 14:40:20] aniismovsa at gmail dot com
Description:
------------
Hello. I think it would be very useful to have otput filtering built in PDO. For example if use
fetchAll() I get raw data which might have XSS javascript inside. Then I have to filter it somehow
e.g. htmlspecialchars.
I think it would be great if such filtering could be done with method like
fetchAllFiltered(array('number','string','html');
For example if i have a table posts and it looks like id, title, body then when calling
fetchAllFiltered('number','string','html') i would get id sanitized as
a number, title sanitized as a string or simply with htmlspecialchars() and a body which would get
sanitized as html. e.g. no javascript inside, but all html tags present.
Currently to filter the data coming from database usually is used filter_var or htmlspecialchars or
anything else which i think is one more step in development which could be dropped using
fetchAllFiltered().
Also i think that filtering could be added in default fetch methods of PDO as an array argument
which describes filtering of output for those methods.
For example: fetchAll(array('number',string','html')); and we get the
filtered output.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66495&edit=1