Re: Bugs in PEAR::DB
| From: | (Oleg Rekutin) | Date: | Thu, 12 Jul 2001 14:19:20 +0000 |
| Subject: | Re: Bugs in PEAR::DB | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-664@lists.php.net to get a copy of this message | ||
Stig.Bakken@fast.no (Stig Bakken) wrote in
news:Pine.BSF.4.10.10107121514150.89490-100000@midten.fast.no:
> On Wed, 11 Jul 2001, Tomas V.V.Cox wrote:
>
>> Any way, in the "draft" I told you after, I proposed to add a new
>> placeholder "!" that will leave unchanged the supplied string (without
>> call $db->quoteString()).
>
> ah, so there is another need for it than for functions? then I'm in
> favor of having "!", it would solve Oleg's problem as well.
I just had a situation where I wished '!' was there. I was writing a
statement for prepare/execute like this: UPDATE users SET fullname=?
password=? WHERE user_id=?
Now, the password is never shown on the user update form, and the idea is
that if a user does not enter anything into the password field, it will
leave the user's password unchanged. If a user does enter a new password,
however, then it is encrypted and overwrites the old password in the
database.
This means that at the time of update, if no password has been specified,
the application does not know what the current password is. The only way for
it to find out is to manually "SELECT password FROM users...". I want to
avoid an extra SELECT, especially if a number of users are being updated
simultaneously in one request.
Without !, I had to write two UPDATE statements, one w/ password=? and the
other without, because I couldn't set the password to '' either (which is
what would happen if I passed in an empty string to execute. Then I had to
stuff the array with row information differently depending on whether
password was there or not and then I had to call execute with the
appropriate statement handle.
With !, I could've written UPDATE users SET fullname=? password=! WHERE
user_id=? and then, if the password *were* updated, I would set the rowinfo
[1] to something like "'$encrypted_password'". However, if the password
weren't updated, I could just set rowinfo[1] to "password" and query "UPDATE
users SET fullname='blah' password=password WHERE user_id='blah'" would be
executed. This would leave password unchanged and just make life easier.
- Oleg