Doc #80453 [Csd]: Documentation example error
| From: | goran_zarkovic at zoho dot com | Date: | Tue, 01 Dec 2020 16:35:24 +0000 |
| Subject: | Doc #80453 [Csd]: Documentation example error | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-18174@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80453&edit=1
ID: 80453
User updated by: goran_zarkovic at zoho dot com
Reported by: goran_zarkovic at zoho dot com
Summary: Documentation example error
Status: Closed
Type: Documentation Problem
Package: Variables related
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
I must say I'm impressed with your quick response. Not that this error is crucial, but if
someone tries to use your example as starting point, at least he/she doesn't have to be
confused with unexpected results...
Previous Comments:
------------------------------------------------------------------------
[2020-12-01 16:24:11] phpdocbot@php.net
Automatic comment on behalf of cmb
Revision: http://git.php.net/?p=doc/en.git;a=commit;h=22529a07ac74b0d85326a819eb2f848971c5af48
Log: Fix #80453: Documentation example error
------------------------------------------------------------------------
[2020-12-01 16:22:08] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=351822
Log: Fix #80453: Documentation example error
Actually, this example should better be rewritten to something simpler or at
least something relevant. However, the unserialize() page has the counter
example, so we postpone that, and apply an odd fix instead.
------------------------------------------------------------------------
[2020-12-01 16:19:29] cmb@php.net
Thanks for reporting in the bugtracker! :)
------------------------------------------------------------------------
[2020-12-01 12:16:35] goran_zarkovic at zoho dot com
Description:
------------
There seems to be an error in serialize() function #1 Example:
<?php
// $session_data contains a multi-dimensional array with session
// information for the current user. We use serialize() to store
// it in a database at the end of the request.
$conn = odbc_connect("webdb", "php", "chicken");
$stmt = odbc_prepare($conn,
"UPDATE sessions SET data = ? WHERE id = ?");
$sqldata = array (serialize($session_data), $_SERVER['PHP_AUTH_USER']);
if (!odbc_execute($stmt, $sqldata)) {
$stmt = odbc_prepare($conn,
"INSERT INTO sessions (id, data) VALUES(?, ?)");
if (!odbc_execute($stmt, $sqldata)) {
/* Something went wrong.. */
}
}
?>
SQL INSERT will result in data and id columns content inverted: $sqldata array contains session_data
and id, so positional data binding will have effect of column id containing session_data, and column
data containing PHP_AUTH_USER.
Proposed correction:
<?php
// $session_data contains a multi-dimensional array with session
// information for the current user. We use serialize() to store
// it in a database at the end of the request.
$conn = odbc_connect("webdb", "php", "chicken");
$stmt = odbc_prepare($conn,
"UPDATE sessions SET data = ? WHERE id = ?");
$sqldata = array (serialize($session_data), $_SERVER['PHP_AUTH_USER']);
if (!odbc_execute($stmt, $sqldata)) {
$stmt = odbc_prepare($conn,
"INSERT INTO sessions (id, data) VALUES(?, ?)");
$sqldata = array ($_SERVER['PHP_AUTH_USER'], serialize($session_data) );
if (!odbc_execute($stmt, $sqldata)) {
/* Something went wrong.. */
}
}
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80453&edit=1