Re: Bugs in PEAR::DB
| From: | Stig Bakken | Date: | Thu, 12 Jul 2001 13:11:22 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-660@lists.php.net to get a copy of this message | ||
On Wed, 11 Jul 2001, Tomas V.V.Cox wrote:
> Oleg Rekutin wrote:
> >
> > Hi, I've been using the DB module in a project and found a few glitches.
> >
> > First of all, prepare/execute has a bug around this part:
> >
> > function executeEmulateQuery($stmt, $data = false)
> > {
> >
> > $p = &$this->prepare_tokens;
> > $stmt = (int)$this->prepare_maxstmt++;
> >
> > if (!isset($this->prepare_tokens[$stmt]) ||
> > !is_array($this->prepare_tokens[$stmt]) ||
> > !sizeof($this->prepare_tokens[$stmt])) {
> > return $this->raiseError(DB_ERROR_INVALID);
> > }
>
> Fixed in CVS, thanks for the solution. Also thanks to Paul who repported
> this some time ago.
>
> > Not really an error, but why does executeEmulateQuery passes the given data
> > thru DB::common::quoteString, while the DB::common::query doesn't? This is
> > the code:
>
> I see this in that way: In some cases Pear offers two ways of doing
> things, one manual/general and one comfortable/specific. For example,
> you can always fetch rows by hand or alternative you can use the get*()
> methods to quick retrieve data.
> In this case, you can build the query by hand (escape, NULLs, etc) in
> your code and call DB query() later or alternative you can use
> prepare/execute who will do the job for you.
>
> > Are users of DB::common::query expected to do it by themselves? Why aren't
> > they then expected to manually quoteString the array that they pass in to
> > execute? Thing is, if the users do quoteString (or the equivalent) the
> > passed in array, then executeEmulateQuery ends up quoting it again.
>
> Pre-quoting the data to be passed to execute is an error.
>
> >On many
> > installations, PHP also automatically quotes the POST and GET information.
> > In order to store such automatically-quoted information with
> > executeEmulateQuery, the users would be forced to unquote the data before
> > passing it in to execute... that's silly, if you ask me.
>
> Yes, this is true. What is the solution here? Detect if magic_quotes are
> set, unquote the string and pass it to $db->quote (who should quote
> according the backend)?
imho the right solution is to tell people to disable magic quotes of any
kind. they're evil.
- Stig