Doc #77531 [Opn]: MySQLi example code promotes bad security practice

From: Date: Mon, 28 Jan 2019 12:50:04 +0000
Subject: Doc #77531 [Opn]: MySQLi example code promotes bad security practice
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-16374@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77531&edit=1

 ID:                 77531
 Updated by:         girgias@php.net
 Reported by:        marcus dot watson at loumiaconsulting dot com
-Summary:            MySQLi example code promotes security bad practice
+Summary:            MySQLi example code promotes bad security practice
 Status:             Open
 Type:               Documentation Problem
-Package:            Documentation problem
+Package:            MySQLi related
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

Hello Marcus,

First of all, thank you for pointing this out and be willing to collaborate.

The best way to proceed would be for you to edit the documentation with the help of the online doc
editor located at https://edit.php.net (or use the direct link
from the manual to edit this specific page https://edit.php.net/?project=PHP&perm=en/mysqli.examples-basic.php)

After having edited the corresponding XML file, submit a patch via the editor and optionally submit
the patch to this bug report.
So that a member of the doc team can review it and accept it.

Best regards.


Previous Comments:
------------------------------------------------------------------------
[2019-01-27 22:48:47] marcus dot watson at loumiaconsulting dot com

Description:
------------
---
From manual page: https://php.net/mysqli.examples-basic
---

If this is to be a basic example of database handling and you do not want to use parameterization or
promote security for the sake of brevity, I suggest using an approach that does not include string
concatenation.

The current example is a bad habit to promote to developers. Developers unaware of SQL injection
will focus on the "$result = $mysqli->query($sql)" part and omit any validation that
has been performed previously. Typical InfoSec best practice dictates implementing parameterization
first, *then* validation.


Suggested alternative: Use a hard coded query to return a status (eg total number of actors/movies
in the database, or who is the customer with the largest number of fines).

Leave the dynamic queries for another example altogether, where the correct approach can be
demonstrated, and cross-referenced from this page if dynamic queries are required.

This approach would demonstrate static queries with single/multiple rows. The more complex example
would include dynamic queries with single/multiple rows, thus covering the main scenarios that teams
would encounter.


I'm happy to collaborate with the assignee to formulate the code.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77531&edit=1


Thread (4 messages)

« previous php.doc.bugs (#16374) next »