Req #66355 [Opn]: PDO::FETCH_INTO $this + protected properties throws Fatal error

From: Date: Thu, 06 May 2021 15:36:26 +0000
Subject: Req #66355 [Opn]: PDO::FETCH_INTO $this + protected properties throws Fatal error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233719@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66355&edit=1 ID: 66355 Updated by: cmb@php.net Reported by: sjon at hortensius dot net Summary: PDO::FETCH_INTO $this + protected properties throws Fatal error Status: Open Type: Feature/Change Request Package: PDO related Operating System: archlinux PHP Version: 5.5.7 Block user comment: N Private report: N New Comment: > […] , but why can't FETCH_INTO do the same (for $this)? Because PDO doe not provide a fake scope for FETCH_INTO, so the property is set from PDOStatement where modifications of protected User properties are not allowed. From looking at commit 883ee83478[1], this looks unintentional. *Simplified* PoC fix: ext/pdo/pdo_stmt.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ext/pdo/pdo_stmt.c b/ext/pdo/pdo_stmt.c index adc921bbd7..45d22d5152 100644 --- a/ext/pdo/pdo_stmt.c +++ b/ext/pdo/pdo_stmt.c @@ -1082,7 +1082,7 @@ static int do_fetch(pdo_stmt_t *stmt, int do_bind, zval *return_value, enum pdo_ case PDO_FETCH_OBJ: case PDO_FETCH_INTO: - zend_update_property_ex(NULL, return_value, + zend_update_property_ex(Z_OBJCE_P(return_value), return_value, stmt->columns[i].name, &val); zval_ptr_dtor(&val); [1] <https://github.com/php/php-src/commit/883ee83478177ebb220bef6634dcc2c6749a8625> Previous Comments: ------------------------------------------------------------------------ [2013-12-26 15:41:18] sjon at hortensius dot net Description: ------------ I like FETCH_CLASS being able to put stuff in protected properties, but why can't FETCH_INTO do the same (for $this)? Test script: --------------- <?php class User { protected $id; public static function get() { global $db; $q = $db->query("SELECT * FROM User WHERE id = 1"); $q->setFetchMode(PDO::FETCH_CLASS, 'User'); return $q->fetch(); } public function load() { global $db; $q = $db->query("SELECT * FROM User WHERE id = 1"); $q->setFetchMode(PDO::FETCH_INTO, $this); return $q->fetch(); } } $db = new PDO('sqlite::memory:'); $db->exec("CREATE TABLE User(id INTEGER PRIMARY KEY, name TEXT)"); $db->query("INSERT INTO User VALUES(1, 'test')"); // worko var_dump(User::get()); // no-worko $user = new User; var_dump($user->load()); Expected result: ---------------- Both var_dumps should return the same object Actual result: -------------- object(User)#3 (2) { ["id":protected]=> string(1) "1" ["name"]=> string(4) "test" } Fatal error: Cannot access protected property User::$id in /in/DCjXc on line 24 Process exited with code 255. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66355&edit=1

« previous php.bugs (#233719) next »