RE: [PEAR-DEV] RE: [PEAR] Problem using PEAR::DB
| From: | Dennis Sterzenbach | Date: | Sun, 28 Sep 2003 16:25:44 +0000 |
| Subject: | RE: [PEAR-DEV] RE: [PEAR] Problem using PEAR::DB | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-22129@lists.php.net to get a copy of this message | ||
> IMO "batch queries" are a potential security problem. One of pending
> things in PEAR DB is to ensure the complete avoid of them if the
> php driver doesn't do it.
>
I don't think batch queries are a security problem themselves.
It's more likely insertion of sql. But that has nothing to do with each
other, neither, IMHO, is worth discussing.
If you think of batch queries might be used to make MySQL explode,
you shouldn't even allow to call simpleQuery() more than strictly
defined
amount of times.
> Btw, adding to simpleQuery() the code necesary for splitting queries
> would become in a high performance loss.
>
IMO noone thought about extending simpleQuery()
That would rather slow down, either mean a potential loss of stability.
If I should ever add batch querying features to the current Framework,
I'd define a different function like batchQuery().
> If you want to launch multiple queries, just call multiple times
> "query".
Sure, in my Wrapper I've done so: I Implemented a batchQuery() function,
explode()'ing a String into an Array of statements (if it's not been
given an Array), then running for-each to call simpleQuery() and
fetch'ing all results to an Array.
The point for me only is the way and problem of storing and delivering
all the results of each query in batch as performant and as memory
saving
as possible.
-Indeed, this could mean sleepless nights.
Whereas It might be better developing in C with PEAR::DB only wrapping
or handing the stuff over.
Regards
--
Dennis Sterzenbach