Doc #77531 [NEW]: MySQLi example code promotes security bad practice
From: marcus dot watson at loumiaconsulting dot com
Operating system:
PHP version: Irrelevant
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:MySQLi example code promotes security bad practice
Description:
------------
---
From manual page: https://php.net/mysqli.examples-basic
---
If this is to be a basic example of database handling and you do not
want to use parameterization or promote security for the sake of
brevity, I suggest using an approach that does not include string
concatenation.
The current example is a bad habit to promote to developers. Developers
unaware of SQL injection will focus on the "$result =
$mysqli->query($sql)" part and omit any validation that has been
performed previously. Typical InfoSec best practice dictates
implementing parameterization first, *then* validation.
Suggested alternative: Use a hard coded query to return a status (eg
total number of actors/movies in the database, or who is the customer
with the largest number of fines).
Leave the dynamic queries for another example altogether, where the
correct approach can be demonstrated, and cross-referenced from this
page if dynamic queries are required.
This approach would demonstrate static queries with single/multiple
rows. The more complex example would include dynamic queries with
single/multiple rows, thus covering the main scenarios that teams would
encounter.
I'm happy to collaborate with the assignee to formulate the code.
--
Edit bug report at https://bugs.php.net/bug.php?id=77531&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77531&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77531&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77531&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77531&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77531&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77531&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77531&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77531&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77531&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77531&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77531&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77531&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77531&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77531&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77531&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77531&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77531&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77531&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77531&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77531&r=mysqlcfg
Thread (4 messages)
- marcus dot watson at loumiaconsulting dot com