Skip to content

[5.x] Fix SQL corruption in QueryWatcher when named bindings share a prefix - #1768

Closed
haminh7036 wants to merge 1 commit into
laravel:5.xfrom
haminh7036:fix/query-watcher-named-binding-prefix
Closed

haminh7036 wants to merge 1 commit into
laravel:5.xfrom
haminh7036:fix/query-watcher-named-binding-prefix

Conversation

@haminh7036

Copy link
Copy Markdown
Contributor

When executing raw bulk queries with dynamically indexed named placeholders (e.g. bulk replacing product attributes), QueryWatcher::replaceBindings() matches and replaces prefixes of longer placeholders.

DB::statement('
    REPLACE INTO product_attributes (product_code, column_id, column_value) VALUES 
    (:product_code1, :column_id1, :column_value1),
    ...
    (:product_code10, :column_id10, :column_value10)
', [
    'product_code1' => 'P01', 'column_id1' => 1, 'column_value1' => 'Red',
    ...
    'product_code10' => 'P01', 'column_id10' => 10, 'column_value10' => 'Cotton',
]);

Because :column_value1 is a prefix of :column_value10, QueryWatcher partially replaces :column_value10 and corrupts the logged SQL into 'Red'0.

This PR adds (?![a-zA-Z0-9_]) so the named-binding regex only matches complete parameter names. Regression test included.

(Follow-up to #1765)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants