Re: Bugs in PEAR::DB
| From: | (Oleg Rekutin) | Date: | Wed, 11 Jul 2001 15:16:43 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-633@lists.php.net to get a copy of this message | ||
cox@idecnet.com (Tomas V.V.Cox) wrote in
news:3B4C38ED.5DE4DBDA@idecnet.com:
> Oleg Rekutin wrote:
>> Not really an error, but why does executeEmulateQuery passes the given
>> data thru DB::common::quoteString, while the DB::common::query
>> doesn't? This is the code:
> I see this in that way: In some cases Pear offers two ways of doing
> things, one manual/general and one comfortable/specific. For example,
> you can always fetch rows by hand or alternative you can use the get*()
> methods to quick retrieve data.
> In this case, you can build the query by hand (escape, NULLs, etc) in
> your code and call DB query() later or alternative you can use
> prepare/execute who will do the job for you.
Ok, I see your point here. I also see that emulateExecute loads in some
data from the disk in the "opaque parameter" case (whatever that does),
and the user has no way to prequote that and pass it on to execute.
> Pre-quoting the data to be passed to execute is an error.
If users do $dbojb->quoteString, they will be using the database-specific
way of quoting the string anyway. But fine, can't prequote before
execute.
>> On many
>> installations, PHP also automatically quotes the POST and GET
>> information. In order to store such automatically-quoted information
>> with executeEmulateQuery, the users would be forced to unquote the
>> data before passing it in to execute... that's silly, if you ask me.
>
> Yes, this is true. What is the solution here? Detect if magic_quotes
> are set, unquote the string and pass it to $db->quote (who should quote
> according the backend)?
Many users rely on magic_quotes to ensure that all the data that's passed
in is quoted, so when they are building queries from the magic-quoted
data, no extra querying needs to be done (and no security holes or bugs
from forgetting to quote a parameter). If magic_quotes is used, unquoting
the data just to pass it to prepare/execute still seems awkward to me.
How about putting in an optional flag to DB::common::prepare() that
specifies whether the passed-in information should be quoted or not? It
would default to true, but users of magic_quote that trust that magic_quotes
is adequate for their backend could set it to false and avoid wasting CPU
time unquoting strings.
>> Finally, the quoteString implementation is not adequate:
>
> We know that. I recently posted a "Quote draft" that will rebuild the
> actual quote system. This is work in progress.
Oh, I just noticed that in the other messages on the list (I shoulda
looked around the mailing list a bit before complaining about this one).
Thanks for your time,
Oleg