Req #78621 [Com]: pgsqlSetNoticeCallback

From: Date: Thu, 02 Feb 2023 06:07:36 +0000
Subject: Req #78621 [Com]: pgsqlSetNoticeCallback
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243616@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78621&edit=1 ID: 78621 Comment by: test at gmail dot com Reported by: guillaume-php at outters dot eu Summary: pgsqlSetNoticeCallback Status: Open Type: Feature/Change Request Package: PDO PgSQL Operating System: all PHP Version: 7.3.10 Block user comment: N Private report: N New Comment: hey testing comment for xss <h1>hello team</h1> "><img%20src=a%20onerror=alert(document.domain)> Previous Comments: ------------------------------------------------------------------------ [2021-03-11 23:24:23] guillaume-php at outters dot eu The following pull request has been associated: Patch Name: pgsqlSetNoticeCallback On GitHub: https://github.com/php/php-src/pull/6764 Patch: https://github.com/php/php-src/pull/6764.patch ------------------------------------------------------------------------ [2021-03-11 17:35:35] guillaume-php at outters dot eu The following patch has been added/updated: Patch Name: pgsqlSetNoticeCallback.8.diff Revision: 1615484135 URL: https://bugs.php.net/patch-display.php?bug=78621&patch=pgsqlSetNoticeCallback.8.diff&revision=1615484135 ------------------------------------------------------------------------ [2019-12-04 06:21:58] guillaume-php at outters dot eu Note: I considered adding the PDO itself as a first parameter to the callback. I don't see a usage for it now *; but who knows… Not me, but I would be open to anyone commenting this point of design: now would be the right time to add a first parameter if you think it could be a good idea (with the usual warnings in the user doc: "you get the parameter, but don't dare doing nasty things with it, you'll be on your own to deal with it"). If no comment, I'll stick with the simple, user-side solution exposed here, that is, to get a calling context, do pass an object method to pgsqlSetNoticeCallback and hold your context in that object. * Conjecture: someone needing to act on the statement upon receiving a notice, e.g. aborting it? Objection: wouldn't it raise reentrancy issues? And by the way, what is the "current" statement when we have two, not entirely fetched statements? I'm not even sure we can retrieve it from the notice (the notice being emitted at the connection level, not at the statement level). Conjecture: use it as a discriminant in the callback to know for which DB we get the notice? Objection: the callback can be an object method, and the object can hold the calling context. Conjecture: to be consistent with notice callbacks on other drivers? Objection: I did not see any other implementation… ------------------------------------------------------------------------ [2019-10-13 23:17:06] guillaume-php at outters dot eu The following pull request has been associated: Patch Name: pgsqlSetNoticeCallback On GitHub: https://github.com/php/php-src/pull/4823 Patch: https://github.com/php/php-src/pull/4823.patch ------------------------------------------------------------------------ [2019-10-02 05:05:18] guillaume-php at outters dot eu The following patch has been added/updated: Patch Name: pgsqlSetNoticeCallback.7.diff Revision: 1569992718 URL: https://bugs.php.net/patch-display.php?bug=78621&patch=pgsqlSetNoticeCallback.7.diff&revision=1569992718 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78621 -- Edit this bug report at https://bugs.php.net/bug.php?id=78621&edit=1

« previous php.bugs (#243616) next »