RE: [PEAR] Re: [PEAR-DEV] Re: [PEAR] [ANNOUNCEMENT] Auth-1.3.1RC1 (beta) Released.
| From: | Jay Taylor | Date: | Mon, 14 Aug 2006 07:28:07 +0000 |
| Subject: | RE: [PEAR] Re: [PEAR-DEV] Re: [PEAR] [ANNOUNCEMENT] Auth-1.3.1RC1 (beta) Released. | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-43684@lists.php.net to get a copy of this message | ||
Daniel Convissor wrote:
> In your initial post, I thought you were talking about
> values. I think automatically delimiting identifiers is a bad idea.
>
> Field names entered into queries from program settings like
> this does not constitute SQL injection.
Does it account for someone having previously fed it a quoted fieldname? Or
will it double quote things?
If it can account for that..what is the harm? Dan may have a valid point,
I'm just not sure from what he wrote what makes it a bad idea (other than
that it is not necessary).
What potential problems might we face?
Thanks!
Jay