Req #81260 [Com]: PDOStatement::execute(array $params)

From: Date: Thu, 15 Jul 2021 14:15:26 +0000
Subject: Req #81260 [Com]: PDOStatement::execute(array $params)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235060@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81260&edit=1 ID: 81260 Comment by: suconghou at gmail dot com Reported by: suconghou at gmail dot com Summary: PDOStatement::execute(array $params) Status: Not a bug Type: Feature/Change Request Package: PDO MySQL Operating System: mac PHP Version: 7.3.29 Block user comment: N Private report: N New Comment: the most use case was prepare('where id = ?') and execute([1]) but got sql. where id = '1' not where id = 1 why the latter case was not safer than the former . Previous Comments: ------------------------------------------------------------------------ [2021-07-15 12:19:51] dharman@php.net Thanks for taking the interest in improving PHP, but this is not a bug. Guessing the binding type from the variable contents would lead to terrible bugs. The safest option is to bind everything as a string. PDO does let you avoid binding as strings with methods like bindParam and bindValue. The binding type should correlate to the type of the column in your SQL, not the data that you are sending. Use other binding types only when you are certain of what you are doing and you understand type juggling. ------------------------------------------------------------------------ [2021-07-15 12:00:22] suconghou at gmail dot com Description: ------------ as the https://www.php.net/manual/en/pdostatement.execute.php say, An array of values with as many elements as there are bound parameters in the SQL statement being executed. All values are treated as PDO::PARAM_STR. why not auto detect string and int and others , and set PDO::PARAM_STR and PARAM_INT ... is it difficult ? why we leave it alone for years, I don't know why , we can do fix these small issue to make php better. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81260&edit=1

« previous php.bugs (#235060) next »