Doc #76315 [Ver]: Clarify if colons are actually necessary to bind named placeholders

From: Date: Wed, 09 May 2018 13:27:47 +0000
Subject: Doc #76315 [Ver]: Clarify if colons are actually necessary to bind named placeholders
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-15679@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76315&edit=1 ID: 76315 Updated by: requinix@php.net Reported by: alvaro at demogracia dot com Summary: Clarify if colons are actually necessary to bind named placeholders Status: Verified Type: Documentation Problem Package: PDO Core PHP Version: Irrelevant Block user comment: N Private report: N New Comment: An array to PDOStatement::execute gets bound like it went through bindValue so the deal with colons applies there too. Previous Comments: ------------------------------------------------------------------------ [2018-05-09 13:22:01] alvaro at demogracia dot com I refer to the overall extension, e.g.: <?php $sth = $dbh->prepare('SELECT :text AS greeting FROM DUAL'); $sth->execute(array('text' => 'Hello, World!')); var_dump($sth->fetch(PDO::FETCH_ASSOC)); ?> ... appears to work too despite the respective manual entry [1] showing colons all around. [1] http://php.net/manual/en/pdostatement.execute.php ------------------------------------------------------------------------ [2018-05-09 12:50:07] requinix@php.net You're talking specifically about PDOStatement::bindParam/Value, right? The colon is optional. Internally PDO wants just the plain name so if there is a colon it will be stripped off. ------------------------------------------------------------------------ [2018-05-09 09:44:51] alvaro at demogracia dot com Description: ------------ All around PDO documentation (e.g. [1]) it's suggested that named placeholders use the ":foo" syntax both in SQL code and in parameter binding code. The former is obviously true, the latter is unclear. Omitting colons has always seemed to work in several drivers but I don't know if it's a behaviour to trust and it doesn't seem to be mentioned in documentation. Please also check "What are colons in parameter names used for?" [2] at Stack Overflow. [1] http://php.net/manual/en/pdostatement.bindvalue.php [2] https://stackoverflow.com/questions/17386469/pdo-prepared-statement-what-are-colons-in-parameter-names-used-for Test script: --------------- <?php $dbh = new PDO('mysql:host=localhost', 'test', 'test', array(PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,)); $sth = $dbh->prepare('SELECT :text AS greeting FROM DUAL'); $sth->bindValue('text', 'Hello, World!', PDO::PARAM_STR); $sth->execute(); var_dump($sth->fetch(PDO::FETCH_ASSOC)); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76315&edit=1

« previous php.doc.bugs (#15679) next »