Re: Bugs in PEAR::DB
| From: | Paul DuBois | Date: | Wed, 11 Jul 2001 16:04:35 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-634@lists.php.net to get a copy of this message | ||
At 8:03 PM +0000 7/10/01, Oleg Rekutin wrote:
Not really an error, but why does executeEmulateQuery passes the given data thru DB::common::quoteString, while the DB::common::query doesn't? This is the code:Sure. Why not?$realquery .= "'" . $this->quoteString($pdata) . "'";Are users of DB::common::query expected to do it by themselves? Why aren't
they then expected to manually quoteString the array that they pass in to execute? Thing is, if the users do quoteString (or the equivalent) theBecause that's what placeholders are for. If you construct the entire query string manually for use with query(), you're responsible for quoting. If you use placeholders, you bind the literal data values to the placeholders. That's how other database APIs work, why should PEAR contravene this common convention?
passed in array, then executeEmulateQuery ends up quoting it again. On many installations, PHP also automatically quotes the POST and GET information. In order to store such automatically-quoted information with executeEmulateQuery, the users would be forced to unquote the data before passing it in to execute... that's silly, if you ask me.It's not silly at all. executeEmulateQuery() has no way of knowing whether or not the information you're passing to it came from a POST or GET request, or from something entirely unrelated. -- Paul DuBois, paul@snake.net