Re: Bugs in PEAR::DB
| From: | (Oleg Rekutin) | Date: | Wed, 11 Jul 2001 16:19:30 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-636@lists.php.net to get a copy of this message | ||
paul@snake.net (Paul Dubois) wrote in
news:p04330102b77228406d96@[192.168.0.31]:
> At 8:03 PM +0000 7/10/01, Oleg Rekutin wrote:
>
> Because that's what placeholders are for. If you construct the entire
> query string manually for use with query(), you're responsible for
> quoting. If you use placeholders, you bind the literal data values to
> the placeholders. That's how other database APIs work, why should PEAR
> contravene this common convention?
I see, I was not aware of this convention. No more objection :)
>>passed in array, then executeEmulateQuery ends up quoting it again. On
>>many installations, PHP also automatically quotes the POST and GET
>>information. In order to store such automatically-quoted information
>>with executeEmulateQuery, the users would be forced to unquote the data
>>before passing it in to execute... that's silly, if you ask me.
>
> It's not silly at all. executeEmulateQuery() has no way of knowing
> whether or not the information you're passing to it came from a POST or
> GET request, or from something entirely unrelated.
That's a good point. So, in the end, I'm just hoping for a switch somewhere
(prepare?) to optionally turn off automatic quoting of data for those users
that wish to put that responsibility upon themselves.
- Oleg