Bug #79276 [Ver]: PDO_API int pdo_parse_params() ignores any placeholder between two '\'
| From: | cmb@php.net | Date: | Thu, 20 Feb 2020 12:05:16 +0000 |
| Subject: | Bug #79276 [Ver]: PDO_API int pdo_parse_params() ignores any placeholder between two '\' | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225646@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79276&edit=1
ID: 79276
Updated by: cmb@php.net
Reported by: v-yitam at microsoft dot com
Summary: PDO_API int pdo_parse_params() ignores any
placeholder between two '\'
Status: Verified
Type: Bug
Package: PDO Core
Operating System: Irrelevant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
In my opionion, this should be fixed, but for BC reasons only for
PHP 8. Let's see where the PR goes. :)
Previous Comments:
------------------------------------------------------------------------
[2020-02-20 12:04:05] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #79276: PDO ignores any placeholder between two '\'
On GitHub: https://github.com/php/php-src/pull/5190
Patch: https://github.com/php/php-src/pull/5190.patch
------------------------------------------------------------------------
[2020-02-20 11:21:31] mumumu@php.net
Automatic comment from SVN on behalf of mumumu
Revision: http://svn.php.net/viewvc/?view=revision&revision=349243
Log: Note that PDO parser supports backslash escapes
Cf. bug #79276.
------------------------------------------------------------------------
[2020-02-20 08:22:40] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=349240
Log: Note that PDO parser supports backslash escapes
Cf. bug #79276.
------------------------------------------------------------------------
[2020-02-19 20:04:56] beakerboy99 at yahoo dot com
I'm the person who originlly submitted this as a bug report to Microsoft, who then passed it on
to the PHP-PDO team. I am updating the SQL Server driver for the Drupal CMS. Drupal uses
backslash-escaped strings for LIKE expressions as its standard. SQL Server does not as its default,
but can when specified in the expression as
field LIKE :parameter_x ESCAPE
'\'. When several LIKE expressions are used in one query, an exception is thrown.
The Drupal core testsuite includes a test for this situation.
Other databases use the ESCAPE '{delimiter}' syntax, so this bug will likely
affect those drivers as well.
------------------------------------------------------------------------
[2020-02-19 16:18:55] v-yitam at microsoft dot com
Thanks for your prompt reply. Just wondering if this is going to be fixed or left as "by
design"?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79276
--
Edit this bug report at https://bugs.php.net/bug.php?id=79276&edit=1