Re: RE: [PEAR] Problem using PEAR::DB
| From: | Tomas V.V.Cox | Date: | Sun, 28 Sep 2003 15:50:33 +0000 |
| Subject: | Re: RE: [PEAR] Problem using PEAR::DB | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-22126@lists.php.net to get a copy of this message | ||
Friday, September 26, 2003, 5:49:39 PM, Stefan Neufeind wrote:
> On 26 Sep 2003 at 16:56, patrick.allaert@belgacom.be wrote:
>> >-----Original Message-----
>> >From: Lukas Smith [mailto:smith@backendmedia.com]
>> >Sent: 26 September 2003 16:46
>> >To: 'Dennis Sterzenbach'; 'ML PEAR General PHP.Net'
>> >Subject: RE: [PEAR] Problem using PEAR::DB
>> >
>> >
>> >> From: Dennis Sterzenbach [mailto:dennis@darknoise.homeip.net]
>> >> Sent: Friday, September 26, 2003 4:42 PM
>> >
>> >> I've got a problem using PEAR::DB.
>> >> I'm already used to the PEAR database abstraction layer,
>> >> but never before I stepped that much into detail of
>> >> MySQL and PEAR.
>> >>
>> >> For me there's obviously no problem putting three queries
>> >> in one SQL string using phpMyAdmin, neither executing it
>> >> on shell.
>> >> But if I try to execute a 'simpleQuery($sql)' with an SQL
>> >> as follows:
>> >> $sql = "DELETE FROM logins WHERE uid=8;
>> >> DELETE FROM users_lists WHERE uid=8;
>> >> DELETE FROM users WHERE uid=8;"
>> >
>> >this is called "batch querying" and it is not supported my mysql
>> >(frontbase and mssql support it though).
>> >
>> >Regards,
>> >Lukas
>>
>> Hi,
>>
>> It should be nice having a support for "batch querying" in PEAR::DB...
>> The DB_common should implement a function splitting the queries... and
>> the specific DB_* (mysql, oci8, sybase,..) should call this splitting
>> functions if unable to deal with "batch queries".
>>
>> What do you think about this suggestion ?
> Yes, I think it's a nice idea. And if you e.g. have a look at
> phpMyAdmin that's what the guys over there already did / solved in
> their PHP sources. So it should be possible to use their experience
> and port that part of source - and not make the same splitting-errors
> they maybe had in the past again. Such a generic splitting function
> (maybe returning an array of queries) would be a nice solution.
IMO "batch queries" are a potential security problem. One of pending
things in PEAR DB is to ensure the complete avoid of them if the
php driver doesn't do it.
Btw, adding to simpleQuery() the code necesary for splitting queries
would become in a high performance loss.
If you want to launch multiple queries, just call multiple times
"query".
--
Tomas V.V.Cox mailto:cox@idecnet.com