note 90181 added to pdo.prepare

From: Date: Thu, 09 Apr 2009 08:37:13 +0000
Subject: note 90181 added to pdo.prepare
Groups: php.notes 
Request: Send a blank email to php-notes+get-152991@lists.php.net to get a copy of this message
I don't think that it's bad design to have table names coming from an unsafe source. For example, if you're designing a CMS and give users the power to make their own plugins quite frequently they will do something silly like take a table name from a request. In this instance it should be the database framework that escapes the table name and I think it would be good if there was a better way of doing it than $pdo->prepare("SELECT * FROM ".addslashes($schema)."")->execute(); something like $pdo->prepare("SELECT * FROM ".$pdo->escape($schema)."")->execute(); would be nice. ---- Server IP: 87.124.35.190 Probable Submitter: 78.86.183.235 ---- Manual Page -- http://www.php.net/manual/en/pdo.prepare.php Edit -- https://master.php.net/note/edit/90181 Del: integrated -- https://master.php.net/note/delete/90181/integrated Del: useless -- https://master.php.net/note/delete/90181/useless Del: bad code -- https://master.php.net/note/delete/90181/bad+code Del: spam -- https://master.php.net/note/delete/90181/spam Del: non-english -- https://master.php.net/note/delete/90181/non-english Del: in docs -- https://master.php.net/note/delete/90181/in+docs Del: other reasons-- https://master.php.net/note/delete/90181 Reject -- https://master.php.net/note/reject/90181 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#152991) next »