Re: Re: [ANNOUNCEMENT] Auth-1.3.1RC1 (beta) Released.

From: Date: Mon, 14 Aug 2006 07:37:29 +0000
Subject: Re: Re: [ANNOUNCEMENT] Auth-1.3.1RC1 (beta) Released.
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-43685@lists.php.net to get a copy of this message
Jay Taylor wrote:
Daniel Convissor wrote:
In your initial post, I thought you were talking about values. I think automatically delimiting identifiers is a bad idea. Field names entered into queries from program settings like this does not constitute SQL injection.
Does it account for someone having previously fed it a quoted fieldname? Or will it double quote things? If it can account for that..what is the harm? Dan may have a valid point, I'm just not sure from what he wrote what makes it a bad idea (other than that it is not necessary). What potential problems might we face?
I doubt he has added quote to add previous quoting, nor is this really easily possible since some RDBMS quote differently. regards, Lukas

« previous php.pear.dev (#43685) next »