Bug #79131 [Ver]: PDO does not throw an exception when parameter values are missing
Edit report at https://bugs.php.net/bug.php?id=79131&edit=1
ID: 79131
Updated by: adambaratz@php.net
Reported by: love at sickpeople dot se
Summary: PDO does not throw an exception when parameter
values are missing
Status: Verified
Type: Bug
-Package: PDO related
+Package: PDO MySQL
PHP Version: 7.4.1
Block user comment: N
Private report: N
New Comment:
I think this bug is specific to pdo_mysql. At least, it's not an issue with pdo_sqlite. If
helpful, I turned the test case into a .phpt file:
https://github.com/adambaratz/php-src/commit/e905da74accf1291000d4ee4f8f1c071fb6f3dee
Previous Comments:
------------------------------------------------------------------------
[2020-01-17 12:46:56] cmb@php.net
This is closely related to bug #79132, but it's not quite a
duplicate, because removing the first two values of $set still
triggers the reported behavior. The issue is that only the number
of elements are checked, not their keys, although the
documentation states[1]:
| The keys from input_parameters must match the ones declared in
| the SQL. Before PHP 5.2.0 this was silently ignored.
[1] <https://www.php.net/manual/en/pdostatement.execute.php#refsect1-pdostatement.execute-changelog>
------------------------------------------------------------------------
[2020-01-17 12:41:39] cmb@php.net
Related To: Bug #79132
------------------------------------------------------------------------
[2020-01-16 15:33:13] love at sickpeople dot se
Description:
------------
In the test script I execute the same statement three times. The last execution has two parameters
but the second parameter has array key 2 instead of 1 and is thus missing.
PDO returns false instead of throwing an exception.
Note that emulated PREPARE must be disabled.
Test script:
---------------
$host = '';
$db = '';
$user = '';
$pass = '';
$options = [
PDO::ATTR_EMULATE_PREPARES => false, /* required */
PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
];
$pdo = new PDO("mysql:host=$host; dbname=$db; charset=utf8mb4", $user, $pass, $options);
$stmt = $pdo->prepare('select ? a, ? b');
$set = [
['a', 'b'],
[0 => 'a', 1 => 'b'],
[0 => 'a', 2 => 'b'], /* Note the array keys */
];
foreach ($set as $params) {
try {
var_dump($stmt->execute($params), $stmt->fetchAll(PDO::FETCH_ASSOC));
}
catch (Throwable $error) {
echo $error->getMessage() . "\n";
}
}
Expected result:
----------------
If emulated PREPARE is enabled, an error "SQLSTATE[HY093]: Invalid parameter number: parameter
was not defined" is issued. The same error should be thrown as an exception.
Actual result:
--------------
bool(true)
array(1) {
[0]=>
array(2) {
["a"]=>
string(1) "a"
["b"]=>
string(1) "b"
}
}
bool(true)
array(1) {
[0]=>
array(2) {
["a"]=>
string(1) "a"
["b"]=>
string(1) "b"
}
}
bool(false)
array(0) {
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79131&edit=1
Thread (5 messages)