RE: [PEAR-DEV] RE: [PEAR] Problem using PEAR::DB

From: Date: Sun, 28 Sep 2003 16:25:44 +0000
Subject: RE: [PEAR-DEV] RE: [PEAR] Problem using PEAR::DB
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-22129@lists.php.net to get a copy of this message
> IMO "batch queries" are a potential security problem. One of pending > things in PEAR DB is to ensure the complete avoid of them if the > php driver doesn't do it. > I don't think batch queries are a security problem themselves. It's more likely insertion of sql. But that has nothing to do with each other, neither, IMHO, is worth discussing. If you think of batch queries might be used to make MySQL explode, you shouldn't even allow to call simpleQuery() more than strictly defined amount of times. > Btw, adding to simpleQuery() the code necesary for splitting queries > would become in a high performance loss. > IMO noone thought about extending simpleQuery() That would rather slow down, either mean a potential loss of stability. If I should ever add batch querying features to the current Framework, I'd define a different function like batchQuery(). > If you want to launch multiple queries, just call multiple times > "query". Sure, in my Wrapper I've done so: I Implemented a batchQuery() function, explode()'ing a String into an Array of statements (if it's not been given an Array), then running for-each to call simpleQuery() and fetch'ing all results to an Array. The point for me only is the way and problem of storing and delivering all the results of each query in batch as performant and as memory saving as possible. -Indeed, this could mean sleepless nights. Whereas It might be better developing in C with PEAR::DB only wrapping or handing the stuff over. Regards -- Dennis Sterzenbach

« previous php.pear.dev (#22129) next »