We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 39156
    • 4 Posts
    First off, I need to explain that I come from a Java programming background. However, I now write PHP as my main programming language in my current position. I received a lot of security training in my past job working in Java.

    One of the things that was drilled into us was to rely on the proper use of database prepared statements (see http://en.wikipedia.org/wiki/Prepared_statement) to guard against SQL injection (see https://www.owasp.org/index.php/Preventing_SQL_Injection_in_Java#Prepared_Statements).

    There are some of us that prefer to code the SQL directly instead of using an ORM tool because it allows better control over the SQL syntax.

    I'm kind of surprised that the MODx documentation encourages programmers to manually code input escaping, instead of relying on the database driver to do the work for you by using prepared statements (see http://rtfm.modx.com/display/MODx096/escape). Instead, I would encourage the MODx community to offer examples like the following:

    	$stmt = $modx->prepare("select * from my_table where key = :recordKey");
    	$stmt->bindParam(':recordKey', $key );
    	$stmt->execute();
    	$rows = $stmt->fetchAll(\PDO::FETCH_CLASS);
    


    Anyone agree? What are your thoughts?
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      MODx 0.9.6 is extremely old; pre-Evo, in fact. The documentation is only provided as a service for those who for whatever reason choose not to or cannot upgrade. MODx 2.x "Revolution" is based on, and its documentation encourages using, xPDO, extensions to the PHP PDO drivers, and has done so for quite some time now. And gets flak from time to time from those who prefer the "old" ways wink

      http://rtfm.modx.com/display/xPDO20/What+It+Is
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 39156
        • 4 Posts
        Excellent point. I didn't even think to check the version of the documentation. Sorry about that. Probably a better example would be http://rtfm.modx.com/display/xPDO20/xPDO.query.

        My main point is that I don't think a lot of programmers know that you can rely on the database driver to do the escaping, instead of manually coding it.
          • 39156
          • 4 Posts
          To further illustrate my point, the http://rtfm.modx.com/display/xPDO20/xPDO.query page says the following.
          For single queries that rely on user input, you should manually quote (link to http://us1.php.net/manual/en/pdo.quote.php) the input strings.

          When you visit http://us1.php.net/manual/en/pdo.quote.php it states the following:

          If you are using this function to build SQL statements, you are strongly recommended to use PDO::prepare() to prepare SQL statements with bound parameters instead of using PDO::quote() to interpolate user input into an SQL statement. Prepared statements with bound parameters are not only more portable, more convenient, immune to SQL injection, but are often much faster to execute than interpolated queries, as both the server and client side can cache a compiled form of the query.
            • 43981
            • 7 Posts
            @davedev

            I strongly agree with you. Modx revolution documentation should clearly state to use prepared statements. Rather than asking to use $modx->quote(), they should clearly state to use $modx->prepare()
              • 46067
              • 1 Posts
              I agree....!! But what are the other alternatives of it? If it's not working anymore so??? Are you familiar with Google drive security?
                • 22303 MODX Staff
                • 10,725 Posts
                Quote from: chanchal118 at Nov 10, 2013, 07:11 AM
                @davedev

                I strongly agree with you. Modx revolution documentation should clearly state to use prepared statements. Rather than asking to use $modx->quote(), they should clearly state to use $modx->prepare()

                xPDO objects automatically use prepared statements and bindings internally when used as the documentation shows. This is the advantage of working with xPDO table objects, as you do not need to worry about the details of escaping anything.

                As for places that document the use of ad hoc queries through xPDO, agreed they should encourage the use of prepared statements.