Doc #65370 [NEW]: "Escaping" bullshit again.

From: Date: Thu, 01 Aug 2013 11:38:16 +0000
Subject: Doc #65370 [NEW]: "Escaping" bullshit again.
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-10130@lists.php.net to get a copy of this message
From:             col dot shrapnel at gmail dot com
Operating system: 
PHP version:      Irrelevant
Package:          Documentation problem
Bug Type:         Documentation Problem
Bug description:"Escaping" bullshit again.

Description:
------------
---
From manual page: http://www.php.net/mysqli.quickstart.prepared-statements
---

Some bullshit is written on this documentation page and it have to be
changed.


Test script:
---------------
The page at the moment says:

Bound variables will be escaped automatically by the server. The server
inserts their escaped values at the appropriate places into the statement
template before execution. A hint must be provided to the server for the
type of bound variable, to create an appropriate conversion. See the
mysqli_stmt_bind_param() function for more information.

The automatic escaping of values within the server is sometimes considered
a security feature to prevent SQL injection. The same degree of security
can be achieved with non-prepared statements, if input values are escaped
correctly. 

Expected result:
----------------
While it have to say something like this

"Bound variables are sent to the server completely separated from the query
and thus cannot interfere with it. The server uses these values directly at
the stage of execution, after having statement template parsed. No escaping
ever required for the prepared values as they never being part of the
query. A hint must be provided to the server for the type of bound
variable, to create an appropriate conversion. See the
mysqli_stmt_bind_param() function for more information.

Such a separation sometimes considered as the only security feature to
prevent SQL injection. But the same degree of security can be achieved with
non-prepared statements, if all the SQL literals are formatted correctly.
It have to be noted that correct formatting is not the same as escaping and
involves much more measures than simple escaping. Thus, it is more
convenient and error-proof to use prepared statements". 

Actual result:
--------------
The actual result of the current statement is 1000s of poor PHP monkeys who
were confused about escaping for ages, thanks for bullshit from
mysql_real_escape_string manual page (
https://bugs.php.net/bug.php?id=60398 ) and
still under the same delusion
thanks to this one. 

-- 
Edit bug report at https://bugs.php.net/bug.php?id=65370&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=65370&r=trysnapshot54
Try a snapshot (PHP 5.3):   https://bugs.php.net/fix.php?id=65370&r=trysnapshot53
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=65370&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=65370&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=65370&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=65370&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=65370&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=65370&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=65370&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=65370&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=65370&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=65370&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=65370&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=65370&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=65370&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=65370&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=65370&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=65370&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=65370&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=65370&r=mysqlcfg



Thread (4 messages)

« previous php.doc.bugs (#10130) next »