[PEPr] Comment on Database::SimpleDAO
| From: | David Jean Louis | Date: | Sun, 06 Apr 2008 09:47:02 +0000 |
| Subject: | [PEPr] Comment on Database::SimpleDAO | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-49661@lists.php.net to get a copy of this message | ||
David Jean Louis (http://pear.php.net/user/izi) has commented on the proposal for
Database::SimpleDAO.
Comment:
Not to discourage you, but besides Travis and Alan constructive comments, I
would add:
* die() is not a proper way to report errors to users, use exceptions
instead;
* mysql_* functions belong to the past and should definitively be replaced
by PDO;
* your package does not handle any string quoting: suppose I just want to
insert a string like "That's all right mama"... (worse: it's a critical
security issue);
* you use "SELECT *" everytime (even for counting rows !), what if I don't
want to select all fields ?
Have a look at PDO and existing PEAR Database packages and learn how they
work and handle portability, security, etc... all these things you expect a
db package to provide.
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=547
--
Sent by PEPr, the automatic proposal system at http://pear.php.net