Re: [PATCH - PR] Disable ATTR_EMULATE_PREPARES by default for PDO_Mysql
| From: | Christopher Jones | Date: | Tue, 19 Jun 2012 21:45:37 +0000 |
| Subject: | Re: [PATCH - PR] Disable ATTR_EMULATE_PREPARES by default for PDO_Mysql | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-60894@lists.php.net to get a copy of this message | ||
On 06/16/2012 12:19 AM, Ulf Wendel wrote:
Am 15.06.2012 18:28, schrieb Christopher Jones:We should take this offline - I can see cases where I'd strongly disagree. Chris -- christopher.jones@oracle.com http://twitter.com/#!/ghrdOn 06/15/2012 08:34 AM, Ulf Wendel wrote:Plain wrong. If client does not mess up on type and charsets there is no practical difference between the security of properly done client side escaping and server-side escaping. No matter if the subject of escaping is a fairy tale on goofy or any other string that happens to look like any other human invented format, e.g. SQL. UlfAs long as client-side escaping is done properly, there is no practical difference between the [client vs server -prepare] approaches.The big problem with this line of reasoning is that the client must know exactly the same dialect of SQL/XQUERY/whatever that the server does. Since we can't predict the future, and so a new DB might