#34233 [Fbk->Opn]: PDO ignores parameters when surrounded by closed quotes

From: Date: Fri, 02 Sep 2005 09:23:38 +0000
Subject: #34233 [Fbk->Opn]: PDO ignores parameters when surrounded by closed quotes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-84404@lists.php.net to get a copy of this message
 ID:               34233
 User updated by:  php at sagi dot org
 Reported By:      php at sagi dot org
-Status:           Feedback
+Status:           Open
 Bug Type:         PDO related
 Operating System: Linux
 PHP Version:      5.1.0RC1
 Assigned To:      wez
 New Comment:

Problem still exists with php5-200509020830, pgsql driver. 

Did not test with any other driver.


Previous Comments:
------------------------------------------------------------------------

[2005-09-01 15:15:09] gschlossnagle@php.net

Please try using this CVS snapshot:

  http://snaps.php.net/php5-latest.tar.gz
 
For Windows:
 
  http://snaps.php.net/win32/php5-win32-latest.zip

This works for me in current PHP_5_1 branch using SQLite.

------------------------------------------------------------------------

[2005-08-24 13:23:57] php at sagi dot org

Description:
------------
Running PHP5.1.0RC1, postgresql 8 server with v7.4.7 client libs
(pretty sure native prepared statements are disabled).

When trying to execute this query:
$stmt = $db->prepare("SELECT ('0' || :param || '0')");
$stmt->execute(array(':param' => 123));

PDO actually executes this SQL statement: SELECT ('0' || :param ||
'0'), without replacing :param.

It seems like the parser thinks the whole "0' || :param || '0" part is
quoted, though its not.

The query "SELECT (0 || :param || 0)" works as expected.



------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=34233&edit=1


Thread (8 messages)

« previous php.bugs (#84404) next »