#36281 [Opn->Csd]: bindParam not working with LIKE '%:foo%'
| From: | vrana@php.net | Date: | Wed, 08 Feb 2006 15:29:41 +0000 |
| Subject: | #36281 [Opn->Csd]: bindParam not working with LIKE '%:foo%' | ||
| References: | 1 | Groups: | php.doc |
| Request: | Send a blank email to phpdoc+get-969371882@lists.php.net to get a copy of this message | ||
ID: 36281
Updated by: vrana@php.net
-Summary: dbs
Reported By: vendor at visv dot net
-Status: Open
+Status: Closed
Bug Type: Documentation problem
Operating System: Linux
PHP Version: 5.1.2
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
Previous Comments:
------------------------------------------------------------------------
[2006-02-06 08:28:22] derick@php.net
It's still a good thing to document Dan...
------------------------------------------------------------------------
[2006-02-05 23:28:12] vendor at visv dot net
The code suggested by dbs@php.net in the previous comment
works. I have used this as a basis for a user-contibuted-note
in the online documentation.
Thank you.
------------------------------------------------------------------------
[2006-02-05 18:54:06] dbs@php.net
The bug reporter has erred in assuming that parameters can be replaced
_inside_ delimited strings within the SQL statement; he or she is
treating parameter markers like plain old PHP variables. Of course,
that would lead directly to possible SQL injection, which is exactly
what bound parameters are meant to avoid.
(Also, the sample code provided is missing an ending double-quote on
the first line.)
I'm sure the application will work as intended if rewritten as
follows:
$q = "SELECT id, name FROM test WHERE name like :foo";
$s = "carrot";
$dbh = new PDO('mysql:...', $user, $pass);
$sth = $dbh->prepare($q);
/* prepend and append % around the user-supplied value to match
anywhere in the NAME field */
$s = "%{$s}%";
$sth->bindParam(':foo', $s);
$sth->execute()
while ($r = $sth->fetch()) {
print_r($r);
}
------------------------------------------------------------------------
[2006-02-04 18:54:21] vendor at visv dot net
Possibly. How can we determine that definitively? At the
least, I would like to add a user-note to the online
documentation, if someone cannot add it to the core docs
for pdo-mysql.
The db in question is mysql 4.1
------------------------------------------------------------------------
[2006-02-04 18:49:21] derick@php.net
I doubt this is a bug... many DB APIs simply don't support bind
variables like this. A bind variable is not just any substitution for a
string.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/36281
--
Edit this bug report at http://bugs.php.net/?id=36281&edit=1