Req #38196 [Opn->Sus]: quoteIdentifier() in PDO
| From: | cmb@php.net | Date: | Fri, 16 Jul 2021 14:18:40 +0000 |
| Subject: | Req #38196 [Opn->Sus]: quoteIdentifier() in PDO | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-235085@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=38196&edit=1
ID: 38196
Updated by: cmb@php.net
Reported by: wasti dot redl at gmx dot net
Summary: quoteIdentifier() in PDO
-Status: Open
+Status: Suspended
Type: Feature/Change Request
Package: PDO related
Operating System: Linux
PHP Version: 5.1.4
Block user comment: N
Private report: N
New Comment:
This requires someone to go through the RFC process[1]. For the
time being, I suspend this ticket.
[1] <https://wiki.php.net/rfc/howto>
Previous Comments:
------------------------------------------------------------------------
[2021-03-02 12:51:14] divinity76+spam at gmail dot com
i too want a PDO::quoteIdentifier.
it's been 10.5 years and counting..
------------------------------------------------------------------------
[2014-10-08 00:01:13] cmanley at xs4all dot nl
Hopefully this important (IMHO) feature will be added before we end up in a geriatric ward.
It has only been 8 years so far.
------------------------------------------------------------------------
[2013-09-25 22:12:25] aharvey@php.net
Related To: Bug #65757
------------------------------------------------------------------------
[2010-10-02 10:39:13] + at ni-poc dot com
This would be especially handy if you try to extend PDO to allow extended placeholder syntax. In
that case you normally simply imply that ` is used as field quote and thus defeat the purpose of
using PDO - it isn't cross-DB-compatible anymore.
------------------------------------------------------------------------
[2010-08-02 16:01:24] jo at feuersee dot de
I agree that the current PDO implementation lacks a portable way to quote SQL identifiers like table
or field names.
Some people will argue that in most cases it's better to avoid quote identifiers at all, and I
agree. But every database has it's own list of reserved words which can't be used as a
field or table name unless quoted. As it is hardly possible to avoid all reserved words from all
databases (to improve portability between database backends), implementing such a method in PDO
would be a big help.
Alternative suggestion: instead of adding a new method quoteIdentifier() extend PDO::quote() method
to accept a new const PDO::PARAM_IDENTIFIER which works as follows:
$sql = sprintf("SELECT %s FROM %s",
$pdo->quote('field', PDO::PARAM_IDENTIFIER),
$pdo->quote('table', PDO::PARAM_IDENTIFIER)
);
$sql would then be
for MySQL backend:
SELECT
field FROM table
for SQLite:
SELECT 'field' FROM 'table'
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=38196
--
Edit this bug report at https://bugs.php.net/bug.php?id=38196&edit=1