Bug #79131 [Ver]: PDO does not throw an exception when parameter values are missing

From: Date: Wed, 22 Jan 2020 20:34:06 +0000
Subject: Bug #79131 [Ver]: PDO does not throw an exception when parameter values are missing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225048@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79131&edit=1

 ID:                 79131
 Updated by:         adambaratz@php.net
 Reported by:        love at sickpeople dot se
 Summary:            PDO does not throw an exception when parameter
                     values are missing
 Status:             Verified
 Type:               Bug
-Package:            PDO related
+Package:            PDO MySQL
 PHP Version:        7.4.1
 Block user comment: N
 Private report:     N

 New Comment:

I think this bug is specific to pdo_mysql. At least, it's not an issue with pdo_sqlite. If
helpful, I turned the test case into a .phpt file:
https://github.com/adambaratz/php-src/commit/e905da74accf1291000d4ee4f8f1c071fb6f3dee


Previous Comments:
------------------------------------------------------------------------
[2020-01-17 12:46:56] cmb@php.net

This is closely related to bug #79132, but it's not quite a
duplicate, because removing the first two values of $set still
triggers the reported behavior.  The issue is that only the number
of elements are checked, not their keys, although the
documentation states[1]:

| The keys from input_parameters must match the ones declared in
| the SQL. Before PHP 5.2.0 this was silently ignored.

[1] <https://www.php.net/manual/en/pdostatement.execute.php#refsect1-pdostatement.execute-changelog>

------------------------------------------------------------------------
[2020-01-17 12:41:39] cmb@php.net

Related To: Bug #79132

------------------------------------------------------------------------
[2020-01-16 15:33:13] love at sickpeople dot se

Description:
------------
In the test script I execute the same statement three times. The last execution has two parameters
but the second parameter has array key 2 instead of 1 and is thus missing.

PDO returns false instead of throwing an exception.

Note that emulated PREPARE must be disabled.

Test script:
---------------
$host = '';
$db = '';
$user = '';
$pass = '';

$options = [
    PDO::ATTR_EMULATE_PREPARES => false, /* required */
    PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
  ];

$pdo = new PDO("mysql:host=$host; dbname=$db; charset=utf8mb4", $user, $pass, $options);

$stmt = $pdo->prepare('select ? a, ? b');

$set = [
    ['a', 'b'],
    [0 => 'a', 1 => 'b'],
    [0 => 'a', 2 => 'b'], /* Note the array keys */
  ];

foreach ($set as $params) {

    try {
        var_dump($stmt->execute($params), $stmt->fetchAll(PDO::FETCH_ASSOC));
      }
    catch (Throwable $error) {
        echo $error->getMessage() . "\n";
      }

  }


Expected result:
----------------
If emulated PREPARE is enabled, an error "SQLSTATE[HY093]: Invalid parameter number: parameter
was not defined" is issued. The same error should be thrown as an exception.

Actual result:
--------------
bool(true)
array(1) {
  [0]=>
  array(2) {
    ["a"]=>
    string(1) "a"
    ["b"]=>
    string(1) "b"
  }
}
bool(true)
array(1) {
  [0]=>
  array(2) {
    ["a"]=>
    string(1) "a"
    ["b"]=>
    string(1) "b"
  }
}
bool(false)
array(0) {
}



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79131&edit=1


Thread (5 messages)

« previous php.bugs (#225048) next »