Re: Bugs in PEAR::DB
| From: | Tomas V.V.Cox | Date: | Wed, 11 Jul 2001 11:30:53 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-631@lists.php.net to get a copy of this message | ||
Oleg Rekutin wrote:
>
> Hi, I've been using the DB module in a project and found a few glitches.
>
> First of all, prepare/execute has a bug around this part:
>
> function executeEmulateQuery($stmt, $data = false)
> {
>
> $p = &$this->prepare_tokens;
> $stmt = (int)$this->prepare_maxstmt++;
>
> if (!isset($this->prepare_tokens[$stmt]) ||
> !is_array($this->prepare_tokens[$stmt]) ||
> !sizeof($this->prepare_tokens[$stmt])) {
> return $this->raiseError(DB_ERROR_INVALID);
> }
Fixed in CVS, thanks for the solution. Also thanks to Paul who repported
this some time ago.
> Not really an error, but why does executeEmulateQuery passes the given data
> thru DB::common::quoteString, while the DB::common::query doesn't? This is
> the code:
I see this in that way: In some cases Pear offers two ways of doing
things, one manual/general and one comfortable/specific. For example,
you can always fetch rows by hand or alternative you can use the get*()
methods to quick retrieve data.
In this case, you can build the query by hand (escape, NULLs, etc) in
your code and call DB query() later or alternative you can use
prepare/execute who will do the job for you.
> Are users of DB::common::query expected to do it by themselves? Why aren't
> they then expected to manually quoteString the array that they pass in to
> execute? Thing is, if the users do quoteString (or the equivalent) the
> passed in array, then executeEmulateQuery ends up quoting it again.
Pre-quoting the data to be passed to execute is an error.
>On many
> installations, PHP also automatically quotes the POST and GET information.
> In order to store such automatically-quoted information with
> executeEmulateQuery, the users would be forced to unquote the data before
> passing it in to execute... that's silly, if you ask me.
Yes, this is true. What is the solution here? Detect if magic_quotes are
set, unquote the string and pass it to $db->quote (who should quote
according the backend)?
> Finally, the quoteString implementation is not adequate:
>
> function quoteString($string)
> {
> return str_replace("'", "\'", $string);
> }
>
We know that. I recently posted a "Quote draft" that will rebuild the
actual quote system. This is work in progress.
Tomas V.V.Cox