Re: Bugs in PEAR::DB

From: Date: Thu, 12 Jul 2001 13:15:37 +0000
Subject: Re: Bugs in PEAR::DB
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-661@lists.php.net to get a copy of this message
On Wed, 11 Jul 2001, Tomas V.V.Cox wrote: > On Wednesday 11 July 2001 17:16, you wrote: > > > > Ok, I see your point here. I also see that emulateExecute loads in > > some data from the disk in the "opaque parameter" case (whatever that > > does), and the user has no way to prequote that and pass it on to > > execute. > > > > > Pre-quoting the data to be passed to execute is an error. > > > > If users do $dbojb->quoteString, they will be using the > > database-specific way of quoting the string anyway. But fine, can't > > prequote before execute. > > If the data is binary I think it shouldn't be quoted, but if it's text > yes. Sorry I haven't treated with BLOBs and I can not say much here. > Perhaps someone can give more information on this topic. > > > >> On many > > >> installations, PHP also automatically quotes the POST and GET > > >> information. In order to store such automatically-quoted > > >> information with executeEmulateQuery, the users would be forced to > > >> unquote the data before passing it in to execute... that's silly, > > >> if you ask me. > > > > > > Yes, this is true. What is the solution here? Detect if > > > magic_quotes are set, unquote the string and pass it to $db->quote > > > (who should quote according the backend)? > > > > Many users rely on magic_quotes to ensure that all the data that's > > passed in is quoted, so when they are building queries from the > > magic-quoted data, no extra querying needs to be done (and no > > security holes or bugs from forgetting to quote a parameter). If > > magic_quotes is used, unquoting the data just to pass it to > > prepare/execute still seems awkward to me. > > > > How about putting in an optional flag to DB::common::prepare() that > > specifies whether the passed-in information should be quoted or not? > > It would default to true, but users of magic_quote that trust that > > magic_quotes is adequate for their backend could set it to false and > > avoid wasting CPU time unquoting strings. > > I think we are mixing concepts. Magic_quotes only adds slashes and is > not a good quote system for inserting it in queries. For example: > a string like: > --hello "this is 'a string-- > might be quoted by magic_quotes_gpc: > --hello \"this is \'a string-- > while for example PostgreSQL needs: > --hello "this is ''a string-- > > This is why I think that people should quote the data with native > $db->quoteString() instead of relaying in magic_quotes. Also in the > magic_quotes doc says that it will escape NULs (I don't know what that > means) while we need to transform a null (php constant) value to a > "NULL" string. > > Any way, in the "draft" I told you after, I proposed to add a new > placeholder "!" that will leave unchanged the supplied string (without > call $db->quoteString()). ah, so there is another need for it than for functions? then I'm in favor of having "!", it would solve Oleg's problem as well. - Stig

« previous php.pear.dev (#661) next »