Re: Bugs in PEAR::DB

From: Date: Wed, 11 Jul 2001 18:09:33 +0000
Subject: Re: Bugs in PEAR::DB
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-637@lists.php.net to get a copy of this message
On Wednesday 11 July 2001 17:16, you wrote: > > Ok, I see your point here. I also see that emulateExecute loads in > some data from the disk in the "opaque parameter" case (whatever that > does), and the user has no way to prequote that and pass it on to > execute. > > > Pre-quoting the data to be passed to execute is an error. > > If users do $dbojb->quoteString, they will be using the > database-specific way of quoting the string anyway. But fine, can't > prequote before execute. If the data is binary I think it shouldn't be quoted, but if it's text yes. Sorry I haven't treated with BLOBs and I can not say much here. Perhaps someone can give more information on this topic. > >> On many > >> installations, PHP also automatically quotes the POST and GET > >> information. In order to store such automatically-quoted > >> information with executeEmulateQuery, the users would be forced to > >> unquote the data before passing it in to execute... that's silly, > >> if you ask me. > > > > Yes, this is true. What is the solution here? Detect if > > magic_quotes are set, unquote the string and pass it to $db->quote > > (who should quote according the backend)? > > Many users rely on magic_quotes to ensure that all the data that's > passed in is quoted, so when they are building queries from the > magic-quoted data, no extra querying needs to be done (and no > security holes or bugs from forgetting to quote a parameter). If > magic_quotes is used, unquoting the data just to pass it to > prepare/execute still seems awkward to me. > > How about putting in an optional flag to DB::common::prepare() that > specifies whether the passed-in information should be quoted or not? > It would default to true, but users of magic_quote that trust that > magic_quotes is adequate for their backend could set it to false and > avoid wasting CPU time unquoting strings. I think we are mixing concepts. Magic_quotes only adds slashes and is not a good quote system for inserting it in queries. For example: a string like: --hello "this is 'a string-- might be quoted by magic_quotes_gpc: --hello \"this is \'a string-- while for example PostgreSQL needs: --hello "this is ''a string-- This is why I think that people should quote the data with native $db->quoteString() instead of relaying in magic_quotes. Also in the magic_quotes doc says that it will escape NULs (I don't know what that means) while we need to transform a null (php constant) value to a "NULL" string. Any way, in the "draft" I told you after, I proposed to add a new placeholder "!" that will leave unchanged the supplied string (without call $db->quoteString()). Tomas V.V.Cox

« previous php.pear.dev (#637) next »