My employer, Biggs-Gilmore, has been doing several Drupal projects in the past few months. Once of our main clients uses Oracle 10g as their database back-end so we've had to port the Drupal base and additional modules to support this platform.
We've made a handful of changes to this module for that purpose. See the attached patch. Besides adding Oracle-specific table, sequence and trigger definitions, we found that several of the INSERT and UPDATE queries fail. The only cause we found was that %d parameters were being wrapped in single-quotes. Is this necessary? We removed them in our implementation. The database engine casts these values were parsing the query so I believe it would be safe from SQL injection issues.
Any feedback on our changes would be helpful. Thanks.
| Comment | File | Size | Author |
|---|---|---|---|
| ldapauth.patch | 6.44 KB | celstonvml |
Comments
Comment #1
johnbarclay commentedClosing 5.x issues to clean out issue queue.