Kommentare

Serendipity-Handbuch

Garvin am um :

Hi Damian!

Man kann es sich ja auch von seinen Liebsten zu Weihnachten kaufen lassen!

Da es so gut ist, wie beschrieben, ist es nämlich jeden Cent wert. :-)

Viele Grüße, Garvin

Serendipity 1.3.1 released

Garvin am um :

Simone,

thanks for discussing this. We are actually in need of people who use pgsql and s9y and can help in finding a solution.

Additionally to what is stated in http://board.s9y.org/viewtopic.php?t=12402 here's a quick summary: Serendipity uses a single SQL code that runs on all DBs we support (MySQL,SQLite,PGSql,SQRelay). There are only few exceptions to that SQL, namely where DISTINCT vs. GROUP is used, which requires special case for PostgreSQL.

As for implicit casts, we use those in a central place of the code, where basically any involved DB table can contain a column that is matched against a user specified term. At that point in code, plugins can interfer and supply custom joined tables with differing column types, but all need to be generally matched against the key.

So for this, onle the "LIKE" command or "=" term with single quotes (implicit string cast) really works, because at that place in code, the script might not know if it needs to match an integer or a string. To change this would mean that every plugin or code that hooks into those central functions first needs to check which column type a match key is. That would mean additional performance hits as well as changing all plugins that relate to this. This is nearly an impossible task and involves tidious patching of a lot of plugins.

However, this really is a thing where implicit string typecasting makes sense, and I actually fail to see why this is removed in PGSQL, BC-breaking a lot of existing code (not only s9y).

Typecasting should not simply be put up to the application; IMHO it's the job of a database to do actual casting on its own, introspecting the input and other meta information that is. It's just like lazy variable initializing in PHP: You can simply prototype faster if you are not restricted to explicit casting.

Hope that clears up some things and why I see that more of a shortcoming of PGSQL design decisions.

Regards, Garvin

Garvin am um :

Thanks a lot. Will contact jannis.

Freetag plugin updated to prevent XSS

Garvin am um :

If someone can trick you into clicking a link to your own blog, it does not matter if he's an owner, user or visitor of the blog.

This upgrade is mandatory for users of the freetag plugin.