#107 [NEW]: pgsql does not handle BYTEA througth the '&' placeholder in the prepare method

From: Date: Wed, 15 Oct 2003 20:33:13 +0000
Subject: #107 [NEW]: pgsql does not handle BYTEA througth the '&' placeholder in the prepare method
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-22712@lists.php.net to get a copy of this message
From: giacomo at tesio dot it Operating system: all PHP version: Irrelevant PHP Bug Type: DB Bug description: pgsql does not handle BYTEA througth the '&' placeholder in the prepare method Description: ------------ The DB quote method doesn't care about the field type it has to quote but just of the php type of the content it has to quote. This cause that the content of a file passed through '&' placeholder in a prepare statement is quoted just like a '?'. But to insert binary data in a PostgreSQL db (and I think in many other) you should quote them with an apropiate function (like pg_escape_bytea ) So I think that the quote method should also get (always) another parameters to switch the TYPE in a better way. I hope I could make myself clear. I could fix this bug and send you my patches, but changing the DB/common interface is a too heavy fix to make it without your permission :-D Reproduce code: --------------- FROM DB/pgsql.php: function quote($str = null) { switch (strtolower(gettype($str))) { case 'null': return 'NULL'; case 'integer': case 'double' : return $str; case 'boolean': return $str ? 'TRUE' : 'FALSE'; case 'string': default: $str = str_replace("'", "''", $str); //PostgreSQL treats a backslash as an escape character. $str = str_replace('\\', '\\\\', $str); return "'$str'"; } } Expected result: ---------------- My solution: function quote($str = null, $type) { if($type == DB_PARAM_OPAQUE) { return "'".pg_escape_bytea($str)."'"; } switch (strtolower(gettype($str))) { case 'null': return 'NULL'; case 'integer': case 'double' : return $str; case 'boolean': return $str ? 'TRUE' : 'FALSE'; case 'string': default: $str = str_replace("'", "''", $str); //PostgreSQL treats a backslash as an escape character. $str = str_replace('\\', '\\\\', $str); return "'$str'"; } } -- Edit bug report at http://pear.php.net/bugs/bug.php?id=107&edit=1 --

« previous php.pear.dev (#22712) next »