Re: Bug 62479
| From: | Will Fitch | Date: | Sun, 19 Jan 2014 02:52:27 +0000 |
| Subject: | Re: Bug 62479 | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71263@lists.php.net to get a copy of this message | ||
Hi!
On Sat, Jan 18, 2014, at 05:57 PM, Stas Malyshev wrote:
> Hi!
>
> > I see no comments from you. The only response I've seen from you was
> > your asking me if the patch was ready (in comments on the bug). Can you
> > please elaborate?
>
> The comment is right in the patch:
>
> https://github.com/willfitch/php-src/commit/06170d344f6b3148d505afd8ae952d3439de9005
> but I have already repeated it here - from the code it follows that if
> the password starts with ' or ends with ', it will not be encoded. Is
> this correct behavior?
My apologies for not seeing the comment in Github. I didn't get notified
by email, so I didn't look. Starting with a quote would technically
work, but ending would not (assuming you're throwing the password in
from the DSN and not parameter). However, I'm not sure this edge is
worth the CPU cycles for checking. Then again, I didn't expect to have
a bug where single quotes are part of the password, so there's always a
surprise.
If you feel it's worth the overhead, I'll add in the additional logic.
> --
> Stanislav Malyshev, Software Architect
> SugarCRM: http://www.sugarcrm.com/
> (408)454-6900 ext. 227