Re: [RFC] Escape PDO "?" parameter placeholder
| From: | Nikita Popov | Date: | Tue, 02 Jul 2019 13:07:30 +0000 |
| Subject: | Re: [RFC] Escape PDO "?" parameter placeholder | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-106125@lists.php.net to get a copy of this message | ||
On Fri, May 31, 2019 at 1:27 PM Matteo Beccati <php@beccati.com> wrote:
> Hi everyone,
>
> following some recent unrest in the comments of the related PR, I've
> decided to invest a bit of time on it and finally move it to draft status:
>
> https://wiki.php.net/rfc/pdo_escape_placeholders
>
> The PR is currently closed, but I will soon rebase and update it.
>
> Any feedback kindly accepted!
>
Friendly reminder that this RFC needs to go into voting until Monday
(preferably earlier) to make it into 7.4.
Here's my feedback:
* I would prefer to make escaping not driver-sensitive, as the current
implementation is. Whether ?? is interpreted as a single ? or ?? should not
depend on the driver.
* I would prefer to use \? instead of ?? for escaping. The former is much
more easily understood by a PHP developer and has less chance of clashing
with operators (PHP itself has a ?? operator, it's not so absurd to think
that it also exists elsewhere). The RFC argues against this because it
makes writing a literal \? harder (which would be \\\\?), but I think that
a) the need for a literal \? seems rather rare and b) double-escaping is
already a well-understood problem for anyone who ever used regular
expressions.
Regards,
Nikita