Bug #79131 [Opn->Ver]: PDO does not throw an exception when parameter values are missing

From: Date: Fri, 17 Jan 2020 12:46:56 +0000
Subject: Bug #79131 [Opn->Ver]: PDO does not throw an exception when parameter values are missing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224960@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79131&edit=1 ID: 79131 Updated by: cmb@php.net Reported by: love at sickpeople dot se Summary: PDO does not throw an exception when parameter values are missing -Status: Open +Status: Verified Type: Bug Package: PDO related PHP Version: 7.4.1 Block user comment: N Private report: N New Comment: This is closely related to bug #79132, but it's not quite a duplicate, because removing the first two values of $set still triggers the reported behavior. The issue is that only the number of elements are checked, not their keys, although the documentation states[1]: | The keys from input_parameters must match the ones declared in | the SQL. Before PHP 5.2.0 this was silently ignored. [1] <https://www.php.net/manual/en/pdostatement.execute.php#refsect1-pdostatement.execute-changelog> Previous Comments: ------------------------------------------------------------------------ [2020-01-17 12:41:39] cmb@php.net Related To: Bug #79132 ------------------------------------------------------------------------ [2020-01-16 15:33:13] love at sickpeople dot se Description: ------------ In the test script I execute the same statement three times. The last execution has two parameters but the second parameter has array key 2 instead of 1 and is thus missing. PDO returns false instead of throwing an exception. Note that emulated PREPARE must be disabled. Test script: --------------- $host = ''; $db = ''; $user = ''; $pass = ''; $options = [ PDO::ATTR_EMULATE_PREPARES => false, /* required */ PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION, ]; $pdo = new PDO("mysql:host=$host; dbname=$db; charset=utf8mb4", $user, $pass, $options); $stmt = $pdo->prepare('select ? a, ? b'); $set = [ ['a', 'b'], [0 => 'a', 1 => 'b'], [0 => 'a', 2 => 'b'], /* Note the array keys */ ]; foreach ($set as $params) { try { var_dump($stmt->execute($params), $stmt->fetchAll(PDO::FETCH_ASSOC)); } catch (Throwable $error) { echo $error->getMessage() . "\n"; } } Expected result: ---------------- If emulated PREPARE is enabled, an error "SQLSTATE[HY093]: Invalid parameter number: parameter was not defined" is issued. The same error should be thrown as an exception. Actual result: -------------- bool(true) array(1) { [0]=> array(2) { ["a"]=> string(1) "a" ["b"]=> string(1) "b" } } bool(true) array(1) { [0]=> array(2) { ["a"]=> string(1) "a" ["b"]=> string(1) "b" } } bool(false) array(0) { } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79131&edit=1

« previous php.bugs (#224960) next »