Re: [HACKERS] PQescapeIdentifier

Поиск
Список
Период
Сортировка
От Christopher Kings-Lynne
Тема Re: [HACKERS] PQescapeIdentifier
Дата
Msg-id 44A09B4C.3050605@familyhealth.com.au
обсуждение исходный текст
Ответ на Re: [HACKERS] PQescapeIdentifier  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-patches
>> I thought of that but I assume we were not accepting user-supplied
>> identifiers for this --- that this was only for application use.  Am I
>> wrong?

Well, yes the plan was to accept user-supplied identifiers...

> If you insist on a practical example, I can certainly imagine someone
> thinking it'd be cool to allow searches on a user-selected column, and
> implementing that by passing the user-given column name straight into
> the query with only PQescapeIdentifier for safety.

Yes, phpPgAdmin sure would.  I imagine this would be a nightmare to
address properly, so perhaps we should remove the function :(


В списке pgsql-patches по дате отправления:

Предыдущее
От: ITAGAKI Takahiro
Дата:
Сообщение: Re: table/index fillfactor control, try 3
Следующее
От: Christopher Kings-Lynne
Дата:
Сообщение: Re: [HACKERS] PQescapeIdentifier