note 71127 added to function.pdo-prepare

From: Date: Mon, 13 Nov 2006 14:07:18 +0000
Subject: note 71127 added to function.pdo-prepare
Groups: php.notes php.notes 
Request: Send a blank email to php-notes+get-119661@lists.php.net to get a copy of this message
Watch out: prepared statements on MySQL barf if you try to pass in substitution tables for sql keywords, table names, view names and field names. For example, this will not work: $stmt = $dbh->prepare("SELECT :sqlAggregate( :fieldName) from :viewName"; You will get a MySQL error 1064 and a very unhelpful error message. In short, you need to do string substitutions into your queries if you want configurable table names, aggregate keywords etc etc. Which doesn't help at all in the "protection from injection attacks" thing. A very annoying discovery. ---- Server IP: 203.202.10.60 Probable Submitter: 124.243.142.107 ---- Manual Page -- http://www.php.net/manual/en/function.pdo-prepare.php Edit -- https://master.php.net/note/edit/71127 Del: integrated -- https://master.php.net/note/delete/71127/integrated Del: useless -- https://master.php.net/note/delete/71127/useless Del: bad code -- https://master.php.net/note/delete/71127/bad+code Del: spam -- https://master.php.net/note/delete/71127/spam Del: non-english -- https://master.php.net/note/delete/71127/non-english Del: in docs -- https://master.php.net/note/delete/71127/in+docs Del: other reasons-- https://master.php.net/note/delete/71127 Reject -- https://master.php.net/note/reject/71127 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#119661) next »