note 90181 added to pdo.prepare
| From: | linusnorton at gmail dot com | Date: | Thu, 09 Apr 2009 08:37:13 +0000 |
| Subject: | note 90181 added to pdo.prepare | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-152991@lists.php.net to get a copy of this message | ||
I don't think that it's bad design to have table names coming from an unsafe source.
For example, if you're designing a CMS and give users the power to make their own plugins quite
frequently they will do something silly like take a table name from a request.
In this instance it should be the database framework that escapes the table name and I think it
would be good if there was a better way of doing it than
$pdo->prepare("SELECT * FROM
".addslashes($schema)."")->execute();
something like
$pdo->prepare("SELECT * FROM
".$pdo->escape($schema)."")->execute();
would be nice.
----
Server IP: 87.124.35.190
Probable Submitter: 78.86.183.235
----
Manual Page -- http://www.php.net/manual/en/pdo.prepare.php
Edit -- https://master.php.net/note/edit/90181
Del: integrated -- https://master.php.net/note/delete/90181/integrated
Del: useless -- https://master.php.net/note/delete/90181/useless
Del: bad code -- https://master.php.net/note/delete/90181/bad+code
Del: spam -- https://master.php.net/note/delete/90181/spam
Del: non-english -- https://master.php.net/note/delete/90181/non-english
Del: in docs -- https://master.php.net/note/delete/90181/in+docs
Del: other reasons-- https://master.php.net/note/delete/90181
Reject -- https://master.php.net/note/reject/90181
Search -- https://master.php.net/manage/user-notes.php