Bug #52221 [Ver->Asn]: Misbehaviour of magic_quotes_runtime (get/set))
| From: | uw@php.net | Date: | Wed, 25 Aug 2010 14:32:47 +0000 |
| Subject: | Bug #52221 [Ver->Asn]: Misbehaviour of magic_quotes_runtime (get/set)) | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-4928@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=52221&edit=1
ID: 52221
Updated by: uw@php.net
Reported by: m dot philipp at coreto dot de
Summary: Misbehaviour of magic_quotes_runtime (get/set))
-Status: Verified
+Status: Assigned
Type: Bug
Package: Documentation problem
Operating System: Windows Server 2008 R2
PHP Version: 5.3.2
-Assigned To:
+Assigned To: mysql
Block user comment: N
New Comment:
Getting quite unsure about the won't fix after discussion with Johannes.
Johannes is correct in arguing that the silent removal of a deprecated
feature could break apps unexpectedly, which is bad because magic quotes
has some security impact.
Maybe adding magic quotes (although they are deprecated) to mysqlnd and
throwing a deprecation warning would be best?
Phillip, thoughts? You re-opened it. Not sure if you noticed I had
changed the category/package: Did you intend to re-open as docs or code
issue?
Previous Comments:
------------------------------------------------------------------------
[2010-08-25 16:28:16] andrey@php.net
Doc Problem, not for user mysql.
------------------------------------------------------------------------
[2010-08-25 16:27:44] andrey@php.net
It should be documented that mysqlnd is a new development and doesn't
implement magic quotes. PDO is a new development too, and doesn't
implement magic quotes too. What can be done is adding a
php_error_docref(E_WARNING) at MINIT/RINIT which will tell the developer
that if mysqlnd is active and magic_quotes is set that it won't work
with mysqli. Also a warning can be thrown at every mysqli call.
------------------------------------------------------------------------
[2010-08-25 15:55:47] uw@php.net
mysqlnd does not support magic quotes any more. It is a deprecated
feature and mysqlnd is new. The documentation should note that.
------------------------------------------------------------------------
[2010-07-19 07:54:20] m dot philipp at coreto dot de
Package correction
------------------------------------------------------------------------
[2010-07-01 14:13:36] m dot philipp at coreto dot de
Description:
------------
The documentation lists the get_magic_quotes_runtime() /
set_magic_quotes_runtime() functions as DEPRECATED as of this PHP
version. They still exist and can be called, but already work
inconsistent. When magic_quotes_runtime
file_get_contents() still escapes data, mysqli_fetch_assoc() does not
anymore.
Test script:
---------------
<?php
set_magic_quotes_runtime(1);
echo "GMQR: ";
var_dump(get_magic_quotes_runtime());
$c = mysqli_connect();
mysqli_select_db($c, "test");
$r = mysqli_query($c, "select t from test;");
$ra = mysqli_fetch_assoc($r);
echo "\nDB test:\n" . $ra['t'];
$f = file_get_contents("test.txt");
echo "\n\nfile test.txt:\n" . $f;
----
Content of "test.txt" and table "t":
backslash: \
slash: /
double backslash: \\
quotes: "
single quotes: '
Expected result:
----------------
Expecting similar behaviour from both function calls, dependent of the
acutal magic_quotes_runtime setting.
-OR-
throwing a fatal or catchable_fatal error that unexpectet results can
occur. A function thould be completely removed instead of marked as
deprecated, when it starts to stop working like before.
Actual result:
--------------
Deprecated: Function set_magic_quotes_runtime() is deprecated in
test.php on line 1
GMQR: int(1)
DB test:
backslash: \
slash: /
double backslash: \\
quotes: "
single quotes: '
file test.txt:
backslash: \\
slash: /
double backslash: \\\\
quotes: \"
single quotes: \'
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=52221&edit=1