#36281 [Opn->Csd]: bindParam not working with LIKE '%:foo%'

From: Date: Wed, 08 Feb 2006 15:29:41 +0000
Subject: #36281 [Opn->Csd]: bindParam not working with LIKE '%:foo%'
References: 1  Groups: php.doc 
Request: Send a blank email to phpdoc+get-969371882@lists.php.net to get a copy of this message
ID: 36281 Updated by: vrana@php.net -Summary: dbs Reported By: vendor at visv dot net -Status: Open +Status: Closed Bug Type: Documentation problem Operating System: Linux PHP Version: 5.1.2 New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2006-02-06 08:28:22] derick@php.net It's still a good thing to document Dan... ------------------------------------------------------------------------ [2006-02-05 23:28:12] vendor at visv dot net The code suggested by dbs@php.net in the previous comment works. I have used this as a basis for a user-contibuted-note in the online documentation. Thank you. ------------------------------------------------------------------------ [2006-02-05 18:54:06] dbs@php.net The bug reporter has erred in assuming that parameters can be replaced _inside_ delimited strings within the SQL statement; he or she is treating parameter markers like plain old PHP variables. Of course, that would lead directly to possible SQL injection, which is exactly what bound parameters are meant to avoid. (Also, the sample code provided is missing an ending double-quote on the first line.) I'm sure the application will work as intended if rewritten as follows: $q = "SELECT id, name FROM test WHERE name like :foo"; $s = "carrot"; $dbh = new PDO('mysql:...', $user, $pass); $sth = $dbh->prepare($q); /* prepend and append % around the user-supplied value to match anywhere in the NAME field */ $s = "%{$s}%"; $sth->bindParam(':foo', $s); $sth->execute() while ($r = $sth->fetch()) { print_r($r); } ------------------------------------------------------------------------ [2006-02-04 18:54:21] vendor at visv dot net Possibly. How can we determine that definitively? At the least, I would like to add a user-note to the online documentation, if someone cannot add it to the core docs for pdo-mysql. The db in question is mysql 4.1 ------------------------------------------------------------------------ [2006-02-04 18:49:21] derick@php.net I doubt this is a bug... many DB APIs simply don't support bind variables like this. A bind variable is not just any substitution for a string. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/36281 -- Edit this bug report at http://bugs.php.net/?id=36281&edit=1

« previous php.doc (#969371882) next »