Re: Bugs in PEAR::DB

From: Date: Wed, 11 Jul 2001 16:04:35 +0000
Subject: Re: Bugs in PEAR::DB
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-634@lists.php.net to get a copy of this message
At 8:03 PM +0000 7/10/01, Oleg Rekutin wrote:
Not really an error, but why does executeEmulateQuery passes the given data thru DB::common::quoteString, while the DB::common::query doesn't? This is the code:
            $realquery .= "'" . $this->quoteString($pdata) . "'";
Are users of DB::common::query expected to do it by themselves? Why aren't
Sure. Why not?
they then expected to manually quoteString the array that they pass in to execute? Thing is, if the users do quoteString (or the equivalent) the
Because that's what placeholders are for. If you construct the entire query string manually for use with query(), you're responsible for quoting. If you use placeholders, you bind the literal data values to the placeholders. That's how other database APIs work, why should PEAR contravene this common convention?
passed in array, then executeEmulateQuery ends up quoting it again. On many installations, PHP also automatically quotes the POST and GET information. In order to store such automatically-quoted information with executeEmulateQuery, the users would be forced to unquote the data before passing it in to execute... that's silly, if you ask me.
It's not silly at all. executeEmulateQuery() has no way of knowing whether or not the information you're passing to it came from a POST or GET request, or from something entirely unrelated. -- Paul DuBois, paul@snake.net

« previous php.pear.dev (#634) next »