Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

PartialSearchFilter: ESCAPE '\' breaks multi-value queries on PostgreSQL with PHP < 8.4 (HY093)

Aperta
#8,642 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
75/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
php, postgresql

Direzione di ricerca

Start by locating PartialSearchFilter and its formatLikeValue() method, then inspect the filter tests for multi-value queries and LIKE ... ESCAPE behavior. Reproduce the reported case with PostgreSQL on PHP 8.3 and check the existing behavior on PHP 8.4. Done means multi-value partial searches work on affected PostgreSQL versions without breaking escaping of % and _ or other supported databases.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

API Platform version(s) affected: 4.4.3

(Doctrine ORM 3.5.0, Doctrine DBAL 3.9.5, PHP 8.3.33 with pdo_pgsql, PostgreSQL 17. The ESCAPE '\' clause is identical on the 4.4, 5.0 and main branches.)

Description

With PostgreSQL on PHP < 8.4, PartialSearchFilter breaks as soon as a bound parameter follows its LIKE ... ESCAPE '\' clause. The most visible case is a multi-value query (?name[]=foo&name[]=bar): the collection request fails with

SQLSTATE[HY093]: Invalid parameter number: parameter was not defined

(first thrown by the pagination count query, Doctrine\ORM\Tools\Pagination\Paginator::count()). A single value works, because its only placeholder comes before the escape literal.

This is related to #8434 (Oracle), but the cause is different. Here the generated SQL is correct, and DBAL's own SQL parser also sees both placeholders:

WHERE f0_.name LIKE ? ESCAPE '\' OR f0_.name LIKE ? ESCAPE '\'

(Connection::quote('\') returns '\' on pdo_pgsql; standard_conforming_strings is on.)

The failure comes from PDO itself. Before PHP 8.4, PDO's generic placeholder scanner treats a backslash inside a quoted string as an escape character, so '\' is read as an unterminated string and every ? after it is ignored. PHP 8.4 introduced driver-specific SQL parsers, and the same query works there.

How to reproduce

Plain PDO, no API Platform or Doctrine involved:

$pdo = new PDO('pgsql:host=...;dbname=...', $user, $password, [PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION]);

// OK: single placeholder, before the escape literal
$pdo->prepare("SELECT 'abc' LIKE ? ESCAPE '\\'")->execute(['%b%']);

// PHP 8.3.33: SQLSTATE[HY093]: Invalid parameter number: parameter was not defined
// PHP 8.4.26: OK
$pdo->prepare("SELECT 'abc' LIKE ? ESCAPE '\\' OR 'abc' LIKE ? ESCAPE '\\'")->execute(['%b%', '%z%']);

// OK on PHP 8.3: no escape clause, or another escape character
$pdo->prepare("SELECT 'abc' LIKE ? OR 'abc' LIKE ?")->execute(['%b%', '%z%']);
$pdo->prepare("SELECT 'abc' LIKE ? ESCAPE '!' OR 'abc' LIKE ? ESCAPE '!'")->execute(['%b%', '%z%']);

With API Platform:

#[ApiResource(operations: [
    new GetCollection(parameters: [
        'name' => new QueryParameter(filter: new PartialSearchFilter()),
    ]),
])]
#[ORM\Entity]
class Book { /* ... string $name ... */ }
GET /books?name=foo                   → 200
GET /books?name[]=foo&name[]=bar      → 500 (HY093)

The legacy SearchFilter with the partial strategy works with the same request, since it emits no ESCAPE clause. So migrating from #[ApiFilter(SearchFilter::class)] to PartialSearchFilter, as the 4.4 deprecation suggests, introduces this regression on PostgreSQL with PHP < 8.4.

Possible Solution

Use an escape character that needs no backslash, for example ESCAPE '!', and escape !, % and _ with it in formatLikeValue(). That avoids this PDO issue, and per #8434 it also suits Oracle. I only verified ESCAPE '!' on PostgreSQL (snippet above).

Additional Context

Verified with the same PostgreSQL 17 server and the same PDO snippet on PHP 8.3.33 (fails) and PHP 8.4.26 (passes). As a workaround, we use a custom FilterInterface implementation that emits LIKE without an ESCAPE clause.

Lingua principale
PHP
Stelle
2.6k
Fork
987
Merge medio
1g 8h
PR unite (30g)
80

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di api-platform/core

Tutte le issue di api-platform/core

Issue simili

Altre issue su PHP

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.