Doc #62361 [Ana->Csd]: SQLite3::escapeString is not binary safe

From: Date: Mon, 27 Jun 2016 14:13:00 +0000
Subject: Doc #62361 [Ana->Csd]: SQLite3::escapeString is not binary safe
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-13639@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62361&edit=1 ID: 62361 Updated by: cmb@php.net Reported by: lgynove at 163 dot com Summary: SQLite3::escapeString is not binary safe -Status: Analyzed +Status: Closed Type: Documentation Problem Package: SQLite related Operating System: * PHP Version: 5.3.14 Assigned To: cmb Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2016-06-27 14:12:37] cmb@php.net Automatic comment from SVN on behalf of cmb Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=339508 Log: Fix #62361: SQLite3::escapeString is not binary safe ------------------------------------------------------------------------ [2016-06-27 14:05:08] cmb@php.net > Even if we made "escape"/"quote" binary safe, it may not work as > expected. I think SQLite3 users should use bind blob. ACK > Is anyone verified manual escaping/quoting works for blob? Do mean escaping by SQLite3::escapeString()? This is not binary safe[1], what has to be documented, so I'm changing to doc bug. [1] <https://3v4l.org/hPH7B> ------------------------------------------------------------------------ [2013-10-26 01:58:35] yohgaki@php.net I've made bug 63419 'feedback'. Even if we made "escape"/"quote" binary safe, it may not work as expected. I think SQLite3 users should use bind blob. Is anyone verified manual escaping/quoting works for blob? ------------------------------------------------------------------------ [2012-11-02 11:26:59] daniel dot kinzler at wikimedia dot de The same problem exists with the SQLite driver for PDO, see bug 63419 ------------------------------------------------------------------------ [2012-06-27 16:44:54] ab@php.net Ok, after digging into the subject i've found sqlite3_bind_blob() here http://www.sqlite.org/c3ref/bind_blob.html . This functionality fully replaces sqlite2's sqlite_encode_binary() in sqlite3. As I can see, it's also implemented and available in PHP http://de2.php.net/manual/de/sqlite3stmt.bindparam.php . It looks pretty much like if we want to have the old behaviour, we should take encode.c from PECL. A sticky point here - I'm not sure that the encoding algorithms are equivalent in both 2 and 3. So we would need also something like ->unescapeString() to get the data back. That could be useful in some cases but anyway redundant in sqlite3. What do you think? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62361 -- Edit this bug report at https://bugs.php.net/bug.php?id=62361&edit=1

« previous php.doc.bugs (#13639) next »