Req #66495 [Opn->Wfx]: fetchAllFiltered() method or alike for PDO

From: Date: Wed, 15 May 2019 20:34:06 +0000
Subject: Req #66495 [Opn->Wfx]: fetchAllFiltered() method or alike for PDO
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220861@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66495&edit=1 ID: 66495 Updated by: peehaa@php.net Reported by: aniismovsa at gmail dot com Summary: fetchAllFiltered() method or alike for PDO -Status: Open +Status: Wont fix Type: Feature/Change Request Package: PDO related Operating System: any PHP Version: 5.5.8 Block user comment: N Private report: N New Comment: Handling data in a way to prevent specific kinds of attacks should be done at the place where it is used. For the specific kinds of attacks you mentioned it makes no sense for the database layer to try (and fail to) handle this. Previous Comments: ------------------------------------------------------------------------ [2014-03-06 14:39:40] narf at devilix dot net -1 ... or rather -2 XSS (or any kind of output filtering) isn't PDO's job. ------------------------------------------------------------------------ [2014-01-16 14:40:20] aniismovsa at gmail dot com Description: ------------ Hello. I think it would be very useful to have otput filtering built in PDO. For example if use fetchAll() I get raw data which might have XSS javascript inside. Then I have to filter it somehow e.g. htmlspecialchars. I think it would be great if such filtering could be done with method like fetchAllFiltered(array('number','string','html'); For example if i have a table posts and it looks like id, title, body then when calling fetchAllFiltered('number','string','html') i would get id sanitized as a number, title sanitized as a string or simply with htmlspecialchars() and a body which would get sanitized as html. e.g. no javascript inside, but all html tags present. Currently to filter the data coming from database usually is used filter_var or htmlspecialchars or anything else which i think is one more step in development which could be dropped using fetchAllFiltered(). Also i think that filtering could be added in default fetch methods of PDO as an array argument which describes filtering of output for those methods. For example: fetchAll(array('number',string','html')); and we get the filtered output. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66495&edit=1

« previous php.bugs (#220861) next »