Doc #62361 [Ana->Csd]: SQLite3::escapeString is not binary safe
| From: | cmb@php.net | Date: | Mon, 27 Jun 2016 14:13:00 +0000 |
| Subject: | Doc #62361 [Ana->Csd]: SQLite3::escapeString is not binary safe | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-13639@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62361&edit=1
ID: 62361
Updated by: cmb@php.net
Reported by: lgynove at 163 dot com
Summary: SQLite3::escapeString is not binary safe
-Status: Analyzed
+Status: Closed
Type: Documentation Problem
Package: SQLite related
Operating System: *
PHP Version: 5.3.14
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2016-06-27 14:12:37] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=339508
Log: Fix #62361: SQLite3::escapeString is not binary safe
------------------------------------------------------------------------
[2016-06-27 14:05:08] cmb@php.net
> Even if we made "escape"/"quote" binary safe, it may not work as
> expected. I think SQLite3 users should use bind blob.
ACK
> Is anyone verified manual escaping/quoting works for blob?
Do mean escaping by SQLite3::escapeString()? This is not binary
safe[1], what has to be documented, so I'm changing to doc bug.
[1] <https://3v4l.org/hPH7B>
------------------------------------------------------------------------
[2013-10-26 01:58:35] yohgaki@php.net
I've made bug 63419 'feedback'.
Even if we made "escape"/"quote" binary safe, it may not work as expected. I
think SQLite3 users should use bind blob.
Is anyone verified manual escaping/quoting works for blob?
------------------------------------------------------------------------
[2012-11-02 11:26:59] daniel dot kinzler at wikimedia dot de
The same problem exists with the SQLite driver for PDO, see bug 63419
------------------------------------------------------------------------
[2012-06-27 16:44:54] ab@php.net
Ok, after digging into the subject i've found sqlite3_bind_blob() here http://www.sqlite.org/c3ref/bind_blob.html .
This functionality fully replaces sqlite2's sqlite_encode_binary() in sqlite3. As I can see,
it's also implemented and available in PHP http://de2.php.net/manual/de/sqlite3stmt.bindparam.php
.
It looks pretty much like if we want to have the old behaviour, we should take encode.c from PECL. A
sticky point here - I'm not sure that the encoding algorithms are equivalent in both 2 and 3.
So we would need also something like ->unescapeString() to get the data back. That could be
useful in some cases but anyway redundant in sqlite3.
What do you think?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62361
--
Edit this bug report at https://bugs.php.net/bug.php?id=62361&edit=1