Re: does "quote" DB filter out all dubious characters preventing sql injection?

From: Date: Fri, 08 Oct 2004 23:55:12 +0000
Subject: Re: does "quote" DB filter out all dubious characters preventing sql injection?
References: 1 2 3 4 5 6 7 8  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-14825@lists.php.net to get a copy of this message
Justin Patrin schrieb:
On Fri, 08 Oct 2004 20:14:20 +0200, CirTap <php@serradeil.de> wrote: [snip]
I'd rather see multiple connection support in DB, so I can connect to different DBs and servers [PHP 4.2+] I'll check if there's a request for that.
What do you mean by this? I routinely connect to both an Oracle server and a mysql server in the same script with DB. I also routinely connect to two different mysql servers in one script.
well, two different servers, and db-flavours, ok. maybe I should have said: two different database on the *same* server? I never managed to do this with PEAR::DB i.e to sync two tables using sth. like INSERT .. INTO destdb.table_x SELECT ... FROM srcdb.table_y eg. $db1 = DB::connect('mysql://user@localhost/db1'); $db2 = DB::connect('mysql://user@localhost/db1'); They always share the same connection handle: same user, same server, different databases. I can do this with native mysql_connect( ... newlink=true), but DB lacks support for this parameter (in 1.62) I often need to integrate my PEARified scripts with 3rd party code/APIs that also make DB conenctions, my PEAR::DB-queries -- using a different database -- tend to work on the wrong connection; or vice versa, whichever connection comes first. For example: I have some forum running on "forum_db@localhost" where I need to get some user data I need for the main website; there's a "API class" which handles all the login/cookie/auth stuff, so it makes a db connection to its forum database. The main site's content is in "site_db@localhost" and my scripts use PEAR::DB. If the first db connection happens thru the Forum-API (different db-layer), my website's PEAR::DB connection "inherits" this handle - and fails. If I connect first, the Forum-API uses "my" db handle and fails, too. Stuck. However, I finally patched the API's db-layer to use "new_link", as this was easier to do :) Sure, there might be something wrong in this procedure :) Maybe you can enlight me on how I can manage this? CirTap

« previous php.pear.general (#14825) next »