Re: Re: [ANNOUNCEMENT] Auth-1.3.1RC1 (beta) Released.
| From: | Lukas Kahwe Smith | Date: | Mon, 14 Aug 2006 07:37:29 +0000 |
| Subject: | Re: Re: [ANNOUNCEMENT] Auth-1.3.1RC1 (beta) Released. | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-43685@lists.php.net to get a copy of this message | ||
Jay Taylor wrote:
Daniel Convissor wrote:I doubt he has added quote to add previous quoting, nor is this really easily possible since some RDBMS quote differently. regards, LukasIn your initial post, I thought you were talking about values. I think automatically delimiting identifiers is a bad idea. Field names entered into queries from program settings like this does not constitute SQL injection.Does it account for someone having previously fed it a quoted fieldname? Or will it double quote things? If it can account for that..what is the harm? Dan may have a valid point, I'm just not sure from what he wrote what makes it a bad idea (other than that it is not necessary). What potential problems might we face?