RE: [PHP-DEV] Expose pdo_parse_params to userspace

From: Date: Wed, 11 Oct 2023 18:45:07 +0000
Subject: RE: [PHP-DEV] Expose pdo_parse_params to userspace
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-121274@lists.php.net to get a copy of this message
> I have to say I am not a fan of this proposal. While definitely a super nice > feature in PDO, it's more of a hack rather than proper feature. > Certain RDBMSs support named parameters in prepared statements, but > MySQL doesn't. Therefore, the solution implemented in PDO is a hack. It's very > flawed and the current implementation has multiple bugs and shortcomings. > One could say that some bugs are security issues. What is the big risk/challenge in converting named bound parameters to positional bound parameters? It seems straightforward. -Jeff

« previous php.internals (#121274) next »