Req #78621 [Com]: pgsqlSetNoticeCallback
| From: | test at gmail dot com | Date: | Thu, 02 Feb 2023 06:07:36 +0000 |
| Subject: | Req #78621 [Com]: pgsqlSetNoticeCallback | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-243616@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78621&edit=1
ID: 78621
Comment by: test at gmail dot com
Reported by: guillaume-php at outters dot eu
Summary: pgsqlSetNoticeCallback
Status: Open
Type: Feature/Change Request
Package: PDO PgSQL
Operating System: all
PHP Version: 7.3.10
Block user comment: N
Private report: N
New Comment:
hey testing comment for xss
<h1>hello team</h1>
"><img%20src=a%20onerror=alert(document.domain)>
Previous Comments:
------------------------------------------------------------------------
[2021-03-11 23:24:23] guillaume-php at outters dot eu
The following pull request has been associated:
Patch Name: pgsqlSetNoticeCallback
On GitHub: https://github.com/php/php-src/pull/6764
Patch: https://github.com/php/php-src/pull/6764.patch
------------------------------------------------------------------------
[2021-03-11 17:35:35] guillaume-php at outters dot eu
The following patch has been added/updated:
Patch Name: pgsqlSetNoticeCallback.8.diff
Revision: 1615484135
URL: https://bugs.php.net/patch-display.php?bug=78621&patch=pgsqlSetNoticeCallback.8.diff&revision=1615484135
------------------------------------------------------------------------
[2019-12-04 06:21:58] guillaume-php at outters dot eu
Note: I considered adding the PDO itself as a first parameter to the callback.
I don't see a usage for it now *; but who knows⦠Not me, but I would be open to anyone
commenting this point of design: now would be the right time to add a first parameter if you think
it could be a good idea (with the usual warnings in the user doc: "you get the parameter, but
don't dare doing nasty things with it, you'll be on your own to deal with it").
If no comment, I'll stick with the simple, user-side solution exposed here, that is, to get a
calling context, do pass an object method to pgsqlSetNoticeCallback and hold your context in that
object.
* Conjecture: someone needing to act on the statement upon receiving a notice, e.g. aborting it?
Objection: wouldn't it raise reentrancy issues? And by the way, what is the "current"
statement when we have two, not entirely fetched statements? I'm not even sure we can retrieve
it from the notice (the notice being emitted at the connection level, not at the statement level).
Conjecture: use it as a discriminant in the callback to know for which DB we get the notice?
Objection: the callback can be an object method, and the object can hold the calling context.
Conjecture: to be consistent with notice callbacks on other drivers?
Objection: I did not see any other implementationâ¦
------------------------------------------------------------------------
[2019-10-13 23:17:06] guillaume-php at outters dot eu
The following pull request has been associated:
Patch Name: pgsqlSetNoticeCallback
On GitHub: https://github.com/php/php-src/pull/4823
Patch: https://github.com/php/php-src/pull/4823.patch
------------------------------------------------------------------------
[2019-10-02 05:05:18] guillaume-php at outters dot eu
The following patch has been added/updated:
Patch Name: pgsqlSetNoticeCallback.7.diff
Revision: 1569992718
URL: https://bugs.php.net/patch-display.php?bug=78621&patch=pgsqlSetNoticeCallback.7.diff&revision=1569992718
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78621
--
Edit this bug report at https://bugs.php.net/bug.php?id=78621&edit=1