Re: Bugs in PEAR::DB
| From: | Stig Bakken | Date: | Thu, 12 Jul 2001 13:15:37 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-661@lists.php.net to get a copy of this message | ||
On Wed, 11 Jul 2001, Tomas V.V.Cox wrote:
> On Wednesday 11 July 2001 17:16, you wrote:
> >
> > Ok, I see your point here. I also see that emulateExecute loads in
> > some data from the disk in the "opaque parameter" case (whatever that
> > does), and the user has no way to prequote that and pass it on to
> > execute.
> >
> > > Pre-quoting the data to be passed to execute is an error.
> >
> > If users do $dbojb->quoteString, they will be using the
> > database-specific way of quoting the string anyway. But fine, can't
> > prequote before execute.
>
> If the data is binary I think it shouldn't be quoted, but if it's text
> yes. Sorry I haven't treated with BLOBs and I can not say much here.
> Perhaps someone can give more information on this topic.
>
> > >> On many
> > >> installations, PHP also automatically quotes the POST and GET
> > >> information. In order to store such automatically-quoted
> > >> information with executeEmulateQuery, the users would be forced to
> > >> unquote the data before passing it in to execute... that's silly,
> > >> if you ask me.
> > >
> > > Yes, this is true. What is the solution here? Detect if
> > > magic_quotes are set, unquote the string and pass it to $db->quote
> > > (who should quote according the backend)?
> >
> > Many users rely on magic_quotes to ensure that all the data that's
> > passed in is quoted, so when they are building queries from the
> > magic-quoted data, no extra querying needs to be done (and no
> > security holes or bugs from forgetting to quote a parameter). If
> > magic_quotes is used, unquoting the data just to pass it to
> > prepare/execute still seems awkward to me.
> >
> > How about putting in an optional flag to DB::common::prepare() that
> > specifies whether the passed-in information should be quoted or not?
> > It would default to true, but users of magic_quote that trust that
> > magic_quotes is adequate for their backend could set it to false and
> > avoid wasting CPU time unquoting strings.
>
> I think we are mixing concepts. Magic_quotes only adds slashes and is
> not a good quote system for inserting it in queries. For example:
> a string like:
> --hello "this is 'a string--
> might be quoted by magic_quotes_gpc:
> --hello \"this is \'a string--
> while for example PostgreSQL needs:
> --hello "this is ''a string--
>
> This is why I think that people should quote the data with native
> $db->quoteString() instead of relaying in magic_quotes. Also in the
> magic_quotes doc says that it will escape NULs (I don't know what that
> means) while we need to transform a null (php constant) value to a
> "NULL" string.
>
> Any way, in the "draft" I told you after, I proposed to add a new
> placeholder "!" that will leave unchanged the supplied string (without
> call $db->quoteString()).
ah, so there is another need for it than for functions? then I'm in favor
of having "!", it would solve Oleg's problem as well.
- Stig