This project is archived and is in readonly mode.
PostgreSQL adapter: quote_string is not thread safe
-
Max Lapshin
- Assigned user set to Tarmo Tänav
Eugene, where is written, that PGconn.escape is unsafe?
-
Eugene Pimenov
>> puts $$ 94100 >> PGconn.escape('test') => "test" >> PGconn.new({}).escape('test') => "test"sudo dtrace -n 'pid94100::PQescapeString:entry { printf("it called me\n") } pid94100::PQescapeStringConn:entry { printf("it called me\n") }' dtrace: description 'pid94100::PQescapeString:entry ' matched 2 probes CPU ID FUNCTION:NAME 1 22323 PQescapeString:entry it called me 0 22324 PQescapeStringConn:entry it called mehttp://www.postgresql.org/docs/8...
PQescapeString can be used safely in single-threaded client programs that work with only one PostgreSQL connection at a time (in this case it can find out what it needs to know "behind the scenes"). In other contexts it is a security hazard and should be avoided in favor of PQescapeStringConn. -
Max Lapshin
- Tag changed from activecord, database, escape, escaping, patch, postgres, postgresql to activecord, bug, database, escape, escaping, patch, postgres, postgresql
+1 This patch works for me, all test passed and it seems to be rather good.
-
Michael Koziarski
- State changed from new to resolved
