Re: Bugs in PEAR::DB

From: Date: Thu, 12 Jul 2001 13:11:22 +0000
Subject: Re: Bugs in PEAR::DB
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-660@lists.php.net to get a copy of this message
On Wed, 11 Jul 2001, Tomas V.V.Cox wrote: > Oleg Rekutin wrote: > > > > Hi, I've been using the DB module in a project and found a few glitches. > > > > First of all, prepare/execute has a bug around this part: > > > > function executeEmulateQuery($stmt, $data = false) > > { > > > > $p = &$this->prepare_tokens; > > $stmt = (int)$this->prepare_maxstmt++; > > > > if (!isset($this->prepare_tokens[$stmt]) || > > !is_array($this->prepare_tokens[$stmt]) || > > !sizeof($this->prepare_tokens[$stmt])) { > > return $this->raiseError(DB_ERROR_INVALID); > > } > > Fixed in CVS, thanks for the solution. Also thanks to Paul who repported > this some time ago. > > > Not really an error, but why does executeEmulateQuery passes the given data > > thru DB::common::quoteString, while the DB::common::query doesn't? This is > > the code: > > I see this in that way: In some cases Pear offers two ways of doing > things, one manual/general and one comfortable/specific. For example, > you can always fetch rows by hand or alternative you can use the get*() > methods to quick retrieve data. > In this case, you can build the query by hand (escape, NULLs, etc) in > your code and call DB query() later or alternative you can use > prepare/execute who will do the job for you. > > > Are users of DB::common::query expected to do it by themselves? Why aren't > > they then expected to manually quoteString the array that they pass in to > > execute? Thing is, if the users do quoteString (or the equivalent) the > > passed in array, then executeEmulateQuery ends up quoting it again. > > Pre-quoting the data to be passed to execute is an error. > > >On many > > installations, PHP also automatically quotes the POST and GET information. > > In order to store such automatically-quoted information with > > executeEmulateQuery, the users would be forced to unquote the data before > > passing it in to execute... that's silly, if you ask me. > > Yes, this is true. What is the solution here? Detect if magic_quotes are > set, unquote the string and pass it to $db->quote (who should quote > according the backend)? imho the right solution is to tell people to disable magic quotes of any kind. they're evil. - Stig

« previous php.pear.dev (#660) next »