My employer, Biggs-Gilmore, has been doing several Drupal projects in the past few months. Once of our main clients uses Oracle 10g as their database back-end so we've had to port the Drupal base and additional modules to support this platform.

We've made a handful of changes to this module for that purpose. See the attached patch. Besides adding Oracle-specific table, sequence and trigger definitions, we found that several of the INSERT and UPDATE queries fail. The only cause we found was that %d parameters were being wrapped in single-quotes. Is this necessary? We removed them in our implementation. The database engine casts these values were parsing the query so I believe it would be safe from SQL injection issues.

Any feedback on our changes would be helpful. Thanks.

CommentFileSizeAuthor
ldapauth.patch6.44 KBcelstonvml

Comments

johnbarclay’s picture

Status: Active » Closed (won't fix)

Closing 5.x issues to clean out issue queue.