Req->Bug #79276 [Opn->Ver]: PDO_API int pdo_parse_params() ignores any placeholder between two '\'
| From: | cmb@php.net | Date: | Sat, 15 Feb 2020 15:23:08 +0000 |
| Subject: | Req->Bug #79276 [Opn->Ver]: PDO_API int pdo_parse_params() ignores any placeholder between two '\' | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225584@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79276&edit=1
ID: 79276
Updated by: cmb@php.net
Reported by: v-yitam at microsoft dot com
Summary: PDO_API int pdo_parse_params() ignores any
placeholder between two '\'
-Status: Open
+Status: Verified
-Type: Feature/Change Request
+Type: Bug
Package: PDO Core
Operating System: Irrelevant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
> If this is intentional (by design), please explain or let us
> know if there is a workaround.
These regexps have been introduced to fix[1] bug #41125 and bug
#44251. Basically, sacrificing some compatibility with standard
SQL in favor of support for MySQL's proprietary backslash
escaping[2].
Proper standard conforming rules would be something like
(["](ANYNOEOF\["]|"")*["]) { RET(PDO_PARSER_TEXT); }
(['](ANYNOEOF\[']|'')*[']) { RET(PDO_PARSER_TEXT); }
Obviously, this could break queries which use backslash escapes.
[1] <http://git.php.net/?p=php-src.git;a=commit;h=1f54af9245c35f2ffdc8c708da9c8552ecada4f8>
[2] <https://dev.mysql.com/doc/refman/8.0/en/string-literals.html>
Previous Comments:
------------------------------------------------------------------------
[2020-02-15 00:19:22] v-yitam at microsoft dot com
Description:
------------
PDO_API int pdo_parse_params() in ext/pdo/pdo_sql_parser.re ignores (skips) any placeholder in
between two backslashes
\
If I replaced the backslash \ with forward slash '/' in the query, the query
succeeded and returned the row as expected.
If the following line is removed the 'problem' is gone:
https://github.com/php/php-src/blob/master/ext/pdo/pdo_sql_parser.re#L59
If this is intentional (by design), please explain or let us know if there is a workaround.
Test script:
---------------
$dbh = new PDO("sqlsrv:server=$server;Database = $db", $uid, $pwd);
$tableName = 'testPDO';
$create_sql = "CREATE TABLE $tableName(id int NOT NULL, langcode varchar(12), revision_id int,
[path] nvarchar(255), [alias] nvarchar(255))"
$dbh->exec($create_sql1);
$insert_sql = "INSERT INTO $tableName(id, langcode, revision_id, [path], [alias]) VALUES (4,
'en', 4, '/node/3', '/')";
$dbh->exec($insert_sql);
$sql = "SELECT * FROM $tableName WHERE [path] LIKE :path ESCAPE '\' AND [langcode]
like :lang ESCAPE '\'";
$args = [
':path' => '%node%',
':lang' => 'en'
];
$sth = $dbh->prepare($sql);
$sth->execute($args);
$row = $sth->fetch(PDO::FETCH_NUM);
var_dump($row);
Expected result:
----------------
array(5) {
[0]=>
string(1) "4"
[1]=>
string(2) "en"
[2]=>
string(1) "4"
[3]=>
string(7) "/node/3"
[4]=>
string(1) "/"
}
Actual result:
--------------
PHP Fatal error: Uncaught PDOException: SQLSTATE[HY093]: Invalid parameter number: parameter was
not defined in C:\Workspace\Test\pdo_1093.php:53
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79276&edit=1