RE: [PHP-DEV] Expose pdo_parse_params to userspace
| From: | Jeffrey Dafoe | Date: | Wed, 11 Oct 2023 18:45:07 +0000 |
| Subject: | RE: [PHP-DEV] Expose pdo_parse_params to userspace | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-121274@lists.php.net to get a copy of this message | ||
> I have to say I am not a fan of this proposal. While definitely a super nice
> feature in PDO, it's more of a hack rather than proper feature.
> Certain RDBMSs support named parameters in prepared statements, but
> MySQL doesn't. Therefore, the solution implemented in PDO is a hack. It's very
> flawed and the current implementation has multiple bugs and shortcomings.
> One could say that some bugs are security issues.
What is the big risk/challenge in converting named bound parameters to positional bound parameters?
It seems straightforward.
-Jeff