Req #38196 [Opn->Sus]: quoteIdentifier() in PDO

From: Date: Fri, 16 Jul 2021 14:18:40 +0000
Subject: Req #38196 [Opn->Sus]: quoteIdentifier() in PDO
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235085@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=38196&edit=1 ID: 38196 Updated by: cmb@php.net Reported by: wasti dot redl at gmx dot net Summary: quoteIdentifier() in PDO -Status: Open +Status: Suspended Type: Feature/Change Request Package: PDO related Operating System: Linux PHP Version: 5.1.4 Block user comment: N Private report: N New Comment: This requires someone to go through the RFC process[1]. For the time being, I suspend this ticket. [1] <https://wiki.php.net/rfc/howto> Previous Comments: ------------------------------------------------------------------------ [2021-03-02 12:51:14] divinity76+spam at gmail dot com i too want a PDO::quoteIdentifier. it's been 10.5 years and counting.. ------------------------------------------------------------------------ [2014-10-08 00:01:13] cmanley at xs4all dot nl Hopefully this important (IMHO) feature will be added before we end up in a geriatric ward. It has only been 8 years so far. ------------------------------------------------------------------------ [2013-09-25 22:12:25] aharvey@php.net Related To: Bug #65757 ------------------------------------------------------------------------ [2010-10-02 10:39:13] + at ni-poc dot com This would be especially handy if you try to extend PDO to allow extended placeholder syntax. In that case you normally simply imply that ` is used as field quote and thus defeat the purpose of using PDO - it isn't cross-DB-compatible anymore. ------------------------------------------------------------------------ [2010-08-02 16:01:24] jo at feuersee dot de I agree that the current PDO implementation lacks a portable way to quote SQL identifiers like table or field names. Some people will argue that in most cases it's better to avoid quote identifiers at all, and I agree. But every database has it's own list of reserved words which can't be used as a field or table name unless quoted. As it is hardly possible to avoid all reserved words from all databases (to improve portability between database backends), implementing such a method in PDO would be a big help. Alternative suggestion: instead of adding a new method quoteIdentifier() extend PDO::quote() method to accept a new const PDO::PARAM_IDENTIFIER which works as follows: $sql = sprintf("SELECT %s FROM %s", $pdo->quote('field', PDO::PARAM_IDENTIFIER), $pdo->quote('table', PDO::PARAM_IDENTIFIER) ); $sql would then be for MySQL backend: SELECT field FROM table for SQLite: SELECT 'field' FROM 'table' ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=38196 -- Edit this bug report at https://bugs.php.net/bug.php?id=38196&edit=1

« previous php.bugs (#235085) next »