blob: e986af85789cfc0052200be5909f902c172a3503 (
plain)
| 1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
 | --TEST--
PDO PgSQL Bug #69362 (PDO-pgsql fails to connect if password contains a leading single quote)
--SKIPIF--
<?php
if (!extension_loaded('pdo') || !extension_loaded('pdo_pgsql')) die('skip not loaded');
require dirname(__FILE__) . '/config.inc';
require dirname(__FILE__) . '/../../../ext/pdo/tests/pdo_test.inc';
PDOTest::skip();
$dsn = getenv('PDOTEST_DSN');
if (empty($dsn)) die('skip no dsn found in env');
$db = PDOTest::test_factory(dirname(__FILE__) . '/common.phpt');
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$user = 'pdo_test_'.rand(5, 400);
$pass = 'testpass';
// Assume that if we can't create or drop a user, this test needs to be skipped
try {
	$db->exec("DROP USER IF EXISTS $user");
	$db->exec("CREATE USER $user WITH PASSWORD '$pass'");
} catch (PDOException $e) {
	die("skip You need CREATEUSER permissions to run the test");
}
// Peer authentication might prevent the test from properly running
try {
	$testConn = new PDO($dsn, $user, $pass);
} catch (PDOException $e) {
	echo "skip ".$e->getMessage();
}
$db->exec("DROP USER $user");
?>
--FILE--
<?php
require dirname(__FILE__) . '/config.inc';
require dirname(__FILE__) . '/../../../ext/pdo/tests/pdo_test.inc';
$pdo = PDOTest::test_factory(dirname(__FILE__) . '/common.phpt');
$pdo->setAttribute(PDO::ATTR_EMULATE_PREPARES, true);
$rand = rand(5, 400);
$user = "pdo_test_$rand";
$template = "CREATE USER $user WITH PASSWORD '%s'";
$dropUser = "DROP USER $user";
$testQuery = 'SELECT 1 as verification';
// Create temp user with leading single quote
$sql = sprintf($template, "''mypassword");
$pdo->query($sql);
$testConn = new PDO($config['ENV']['PDOTEST_DSN'], $user, "'mypassword");
$result = $testConn->query($testQuery)->fetch();
$check = $result[0];
var_dump($check);
// Remove the user
$pdo->query($dropUser);
?>
--EXPECT--
int(1)
 |