phpmyadmin / phpmyadmin/sql-parser

Incorrect parsing of WHERE LIKE with parameter

Open
#253 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement kind/support
Dominant language
PHP
Stars
485
Forks
119
PR merge metrics
No merged PRs in 30d

Description

When trying to parse a WHERE clause such as WHERE foo LIKE :bar it returns foo LIKE : as a single token, where as I would expect it to return foo LIKE :bar as individual tokens. It doesn't have this issue when using back ticks on the columns, or = instead of LIKE.

Sample script:

<?php
require_once __DIR__ . '/vendor/autoload.php';

use PhpMyAdmin\SqlParser\Parser;
use PhpMyAdmin\SqlParser\Token;
use PhpMyAdmin\SqlParser\TokensList;

$sql = 'SELECT * FROM test WHERE foo LIKE :bar';
echo 'sql: ' . $sql . PHP_EOL;
$parser = new Parser($sql);
foreach ($parser->list->tokens as $i => $token) {
    echo 'token: ' . $token->token , PHP_EOL;
}


$sql = 'SELECT * FROM test WHERE `foo` LIKE :bar';
echo 'sql: ' . $sql . PHP_EOL;
$parser = new Parser($sql);
foreach ($parser->list->tokens as $i => $token) {
    echo 'token: ' . $token->token , PHP_EOL;
}

$sql = 'SELECT * FROM test WHERE foo = :bar';
echo 'sql: ' . $sql . PHP_EOL;
$parser = new Parser($sql);
foreach ($parser->list->tokens as $i => $token) {
    echo 'token: ' . $token->token , PHP_EOL;
}

Output:

sql: SELECT * FROM test WHERE foo LIKE :bar
token: SELECT
token:  
token: *
token:  
token: FROM
token:  
token: test
token:  
token: WHERE
token:  
token: foo LIKE :
token: bar
token: 
sql: SELECT * FROM test WHERE `foo` LIKE :bar
token: SELECT
token:  
token: *
token:  
token: FROM
token:  
token: test
token:  
token: WHERE
token:  
token: `foo`
token:  
token: LIKE
token:  
token: :bar
token: 
sql: SELECT * FROM test WHERE foo = :bar
token: SELECT
token:  
token: *
token:  
token: FROM
token:  
token: test
token:  
token: WHERE
token:  
token: foo
token:  
token: =
token:  
token: :bar
token:

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Parser tokenization path using the provided WHERE foo LIKE :bar sample and compare it with the backticked-column and = cases. Trace why the unquoted column, LIKE operator, and named parameter are combined, then add a regression test showing that foo, whitespace, LIKE, whitespace, and :bar are separate tokens.

Written by the indexing model from the issue text.

Assessment

Tech stack
php, sql
Domain
compilers
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.