Re: Bugs in PEAR::DB

From: Date: Wed, 11 Jul 2001 11:30:53 +0000
Subject: Re: Bugs in PEAR::DB
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-631@lists.php.net to get a copy of this message
Oleg Rekutin wrote: > > Hi, I've been using the DB module in a project and found a few glitches. > > First of all, prepare/execute has a bug around this part: > > function executeEmulateQuery($stmt, $data = false) > { > > $p = &$this->prepare_tokens; > $stmt = (int)$this->prepare_maxstmt++; > > if (!isset($this->prepare_tokens[$stmt]) || > !is_array($this->prepare_tokens[$stmt]) || > !sizeof($this->prepare_tokens[$stmt])) { > return $this->raiseError(DB_ERROR_INVALID); > } Fixed in CVS, thanks for the solution. Also thanks to Paul who repported this some time ago. > Not really an error, but why does executeEmulateQuery passes the given data > thru DB::common::quoteString, while the DB::common::query doesn't? This is > the code: I see this in that way: In some cases Pear offers two ways of doing things, one manual/general and one comfortable/specific. For example, you can always fetch rows by hand or alternative you can use the get*() methods to quick retrieve data. In this case, you can build the query by hand (escape, NULLs, etc) in your code and call DB query() later or alternative you can use prepare/execute who will do the job for you. > Are users of DB::common::query expected to do it by themselves? Why aren't > they then expected to manually quoteString the array that they pass in to > execute? Thing is, if the users do quoteString (or the equivalent) the > passed in array, then executeEmulateQuery ends up quoting it again. Pre-quoting the data to be passed to execute is an error. >On many > installations, PHP also automatically quotes the POST and GET information. > In order to store such automatically-quoted information with > executeEmulateQuery, the users would be forced to unquote the data before > passing it in to execute... that's silly, if you ask me. Yes, this is true. What is the solution here? Detect if magic_quotes are set, unquote the string and pass it to $db->quote (who should quote according the backend)? > Finally, the quoteString implementation is not adequate: > > function quoteString($string) > { > return str_replace("'", "\'", $string); > } > We know that. I recently posted a "Quote draft" that will rebuild the actual quote system. This is work in progress. Tomas V.V.Cox

« previous php.pear.dev (#631) next »