[php-src] Issue #8300: Procedural and PDO ODBC don't escape user input when building connection string

From: Date: Tue, 05 Apr 2022 15:33:23 +0000
Subject: [php-src] Issue #8300: Procedural and PDO ODBC don't escape user input when building connection string
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-240670@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/8300
Comment Author: NattyNarwhal

Looking at other ODBC bindings for other languages (Node, .NET, Erlang/OTP), I notice none of them
actually use SQLDriverConnect. They all just take the connection string directly (and
also probably assume you have to use DSN=whatever for the simple case). I wonder if
deprecating the case where PHP appends a connection string could be palatable. It'd definitely
be a big change for users though, and maybe be semantically confusing for PDO.

For another comparison, .NET has some facilities for building connection strings
([generically](https://github.com/dotnet/runtime/blob/57bfe474518ab5b7cfe6bf7424a79ce3af9d6657/src/libraries/System.Data.Common/src/System/Data/Common/DbConnectionOptions.cs)
and [for
ODBC](https://github.com/dotnet/runtime/blob/6a889d234267a4c96ed21d0e1660dce787d78a38/src/libraries/System.Data.Odbc/src/Common/System/Data/Common/DbConnectionOptions.cs)),
and actually seems to note some of the specific rules for quoting/escaping too.


Thread (1 message)

  • NattyNarwhal
« previous php.bugs (#240670) next »