Re: cvs: pear /DB_DataObject/DataObject Cast.php
| From: | Alan Knowles | Date: | Fri, 22 Apr 2005 08:20:45 +0000 |
| Subject: | Re: cvs: pear /DB_DataObject/DataObject Cast.php | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-37333@lists.php.net to get a copy of this message | ||
Yeah that's pretty messy, I probably need more than a few minutes to fix
this one properly..
Regards
Alan
On Thu, 2005-04-21 at 10:18 -0700, Justin Patrin wrote:
> On 4/20/05, Alan Knowles <alan_k@php.net> wrote:
> > alan_k Wed Apr 20 03:35:04 2005 EDT
> >
> > Modified files:
> > /pear/DB_DataObject/DataObject Cast.php
> > Log:
> > fix bug #4182 better string and blob support on mysql in cast
> >
> >
> > http://cvs.php.net/diff.php/pear/DB_DataObject/DataObject/Cast.php?r1=1.12&r2=1.13&ty=u"
> > üâ�øˆSåÈ@í›Ä|
> > Index: pear/DB_DataObject/DataObject/Cast.php
> > diff -u pear/DB_DataObject/DataObject/Cast.php:1.12
> > pear/DB_DataObject/DataObject/Cast.php:1.13
> > --- pear/DB_DataObject/DataObject/Cast.php:1.12 Tue Mar 22 21:35:35 2005
> > +++ pear/DB_DataObject/DataObject/Cast.php Wed Apr 20 03:35:04 2005
> > @@ -17,7 +17,7 @@
> > * @author Alan Knowles <alan@akbkhome.com>
> > * @copyright 1997-2005 The PHP Group
> > * @license http://www.php.net/license/3_0.txt PHP
> > License 3.0
> > - * @version CVS: $Id: Cast.php,v 1.12 2005/03/23 02:35:35 alan_k Exp $
> > + * @version CVS: $Id: Cast.php,v 1.13 2005/04/20 07:35:04 alan_k Exp $
> > * @link http://pear.php.net/package/DB_DataObject
> > */
> >
> > @@ -381,8 +381,14 @@
> > return
> > "'".pg_escape_bytea($this->value)."'::bytea";
> >
> > case 'mysql':
> > - case 'mysqli': // this probably works
> > - return
> > "'".addSlashes($this->value)."'";
> > + return
> > "'".mysql_escape_string($this->value)."'";
> > +
> > + // probably most of the rest could use this! - but it's pretty messy
> > + // as we dont pass the database connection here.
> > + case 'mysqli':
> > + return "'".addslashes($this->value)."'";
> > +
> > +
> >
> > default:
> > return PEAR::raiseError("DB_DataObject_Cast cant handle blobs for
> > Database:$db Yet");
> > @@ -418,6 +424,14 @@
> > case 'pgsql':
> > return
> > "'".pg_escape_string($this->value)."'::bytea";
> >
> > + case 'mysql':
> > + return
> > "'".mysql_escape_string($this->value)."'";
> > +
> > + // this will not work as we dont pass the db connection..! - oops bad design!
> > + //case 'mysqli':
> > + // return
> > "'".mysql_escape_string($this->value)."'";
> > +
> > +
> > default:
> > return PEAR::raiseError("DB_DataObject_Cast cant handle blobs for
> > Database:$db Yet");
> > }
> >
>
> Hmmm....First of all this should really use mysql_real_escape_string()
> although that isn't in older versions of PHP.
>
> Second, for mysqli it should be mysqli_real_escape_string().
>
> Third, $db->quoteSmart() *really* ought to be used here. I would
> suggest altering toString (and all of the other methods) to have a
> real DB parameter. It also really makes no sense to force the user to
> pass in the DB type as DB_DO already knows the DB type.
>
> To keep things simple you could add a function setDatabaseConnection()
> which sets an internal $db var. Then set the DB before you call
> toString. It could also be done with an extra param, but this can't be
> done by ref without a BC break (or PHP5).
>