#107 [NEW]: pgsql does not handle BYTEA througth the '&' placeholder in the prepare method
| From: | giacomo at tesio dot it | Date: | Wed, 15 Oct 2003 20:33:13 +0000 |
| Subject: | #107 [NEW]: pgsql does not handle BYTEA througth the '&' placeholder in the prepare method | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-22712@lists.php.net to get a copy of this message | ||
From: giacomo at tesio dot it
Operating system: all
PHP version: Irrelevant
PHP Bug Type: DB
Bug description: pgsql does not handle BYTEA througth the '&' placeholder in the
prepare method
Description:
------------
The DB quote method doesn't care about the field type it has to quote but
just of the php type of the content it has to quote.
This cause that the content of a file passed through '&' placeholder in a
prepare statement is quoted just like a '?'.
But to insert binary data in a PostgreSQL db (and I think in many other)
you should quote them with an apropiate function (like pg_escape_bytea )
So I think that the quote method should also get (always) another
parameters to switch the TYPE in a better way.
I hope I could make myself clear.
I could fix this bug and send you my patches, but changing the DB/common
interface is a too heavy fix to make it without your permission :-D
Reproduce code:
---------------
FROM DB/pgsql.php:
function quote($str = null)
{
switch (strtolower(gettype($str))) {
case 'null':
return 'NULL';
case 'integer':
case 'double' :
return $str;
case 'boolean':
return $str ? 'TRUE' : 'FALSE';
case 'string':
default:
$str = str_replace("'", "''", $str);
//PostgreSQL treats a backslash as an escape character.
$str = str_replace('\\', '\\\\', $str);
return "'$str'";
}
}
Expected result:
----------------
My solution:
function quote($str = null, $type)
{
if($type == DB_PARAM_OPAQUE)
{
return "'".pg_escape_bytea($str)."'";
}
switch (strtolower(gettype($str))) {
case 'null':
return 'NULL';
case 'integer':
case 'double' :
return $str;
case 'boolean':
return $str ? 'TRUE' : 'FALSE';
case 'string':
default:
$str = str_replace("'", "''", $str);
//PostgreSQL treats a backslash as an escape character.
$str = str_replace('\\', '\\\\', $str);
return "'$str'";
}
}
--
Edit bug report at http://pear.php.net/bugs/bug.php?id=107&edit=1
--