Re: Bugs in PEAR::DB
| From: | Tomas V.V.Cox | Date: | Wed, 11 Jul 2001 18:09:33 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-637@lists.php.net to get a copy of this message | ||
On Wednesday 11 July 2001 17:16, you wrote:
>
> Ok, I see your point here. I also see that emulateExecute loads in
> some data from the disk in the "opaque parameter" case (whatever that
> does), and the user has no way to prequote that and pass it on to
> execute.
>
> > Pre-quoting the data to be passed to execute is an error.
>
> If users do $dbojb->quoteString, they will be using the
> database-specific way of quoting the string anyway. But fine, can't
> prequote before execute.
If the data is binary I think it shouldn't be quoted, but if it's text
yes. Sorry I haven't treated with BLOBs and I can not say much here.
Perhaps someone can give more information on this topic.
> >> On many
> >> installations, PHP also automatically quotes the POST and GET
> >> information. In order to store such automatically-quoted
> >> information with executeEmulateQuery, the users would be forced to
> >> unquote the data before passing it in to execute... that's silly,
> >> if you ask me.
> >
> > Yes, this is true. What is the solution here? Detect if
> > magic_quotes are set, unquote the string and pass it to $db->quote
> > (who should quote according the backend)?
>
> Many users rely on magic_quotes to ensure that all the data that's
> passed in is quoted, so when they are building queries from the
> magic-quoted data, no extra querying needs to be done (and no
> security holes or bugs from forgetting to quote a parameter). If
> magic_quotes is used, unquoting the data just to pass it to
> prepare/execute still seems awkward to me.
>
> How about putting in an optional flag to DB::common::prepare() that
> specifies whether the passed-in information should be quoted or not?
> It would default to true, but users of magic_quote that trust that
> magic_quotes is adequate for their backend could set it to false and
> avoid wasting CPU time unquoting strings.
I think we are mixing concepts. Magic_quotes only adds slashes and is
not a good quote system for inserting it in queries. For example:
a string like:
--hello "this is 'a string--
might be quoted by magic_quotes_gpc:
--hello \"this is \'a string--
while for example PostgreSQL needs:
--hello "this is ''a string--
This is why I think that people should quote the data with native
$db->quoteString() instead of relaying in magic_quotes. Also in the
magic_quotes doc says that it will escape NULs (I don't know what that
means) while we need to transform a null (php constant) value to a
"NULL" string.
Any way, in the "draft" I told you after, I proposed to add a new
placeholder "!" that will leave unchanged the supplied string (without
call $db->quoteString()).
Tomas V.V.Cox