Req #71628 [Opn]: Column names with ? in them confuse the PDO parameter binding

From: Date: Tue, 14 Sep 2021 11:22:49 +0000
Subject: Req #71628 [Opn]: Column names with ? in them confuse the PDO parameter binding
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236582@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71628&edit=1

 ID:                 71628
 Updated by:         cmb@php.net
 Reported by:        californialife88 at hotmail dot com
 Summary:            Column names with ? in them confuse the PDO
                     parameter binding
 Status:             Open
 Type:               Feature/Change Request
 Package:            PDO MySQL
 Operating System:   Windows 7
 PHP Version:        5.6.18
 Block user comment: N
 Private report:     N

 New Comment:

> MySQL, and only MySQL, uses backticks as a way of quoting
> identifiers, but PDO is general purpose so it doesn't know about
> MySQL's idiosyncrasies when it tries to parse the statement
> looking for placeholders.

While PDO indeed ignores backtick quoting, it is aware of
backslash escaping, which is non standard as well (see bug
#79276).

> The only way I could see this being solved is if statement
> parsing was offloaded to the driver instead of being handled by
> vanilla PDO.

That.


Previous Comments:
------------------------------------------------------------------------
[2016-02-19 02:11:02] requinix@php.net

Disable emulated prepares.

MySQL, and only MySQL, uses backticks as a way of quoting identifiers, but PDO is general purpose so
it doesn't know about MySQL's idiosyncrasies when it tries to parse the statement looking
for placeholders.

The only way I could see this being solved is if statement parsing was offloaded to the driver
instead of being handled by vanilla PDO.

------------------------------------------------------------------------
[2016-02-19 01:21:28] californialife88 at hotmail dot com

Description:
------------
This bug has been described well in the following Stack Overflow thread:

http://stackoverflow.com/questions/12092907/php-pdo-insert-to-column-with-question-mark-in-name/35495548#35495548

In particular, please check out the Original Post and the reply by Andre.

Test script:
---------------
INSERT INTO myTable (Id, Title, Expired?) VALUES
(?, ?, ?)

followed by a binding for the 3 variables.

Notice the '?' in one of the column names...

Expected result:
----------------
Insert operation in database

Actual result:
--------------
Error message: "wrong number of parameters passed"


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71628&edit=1


Thread (3 messages)

« previous php.bugs (#236582) next »