Skip to content

2.0.6 - CAST function improvements

Choose a tag to compare

@x86demon x86demon released this 10 Sep 11:51
4dae665

Restricts the target type of the CAST DQL function to the supported type names and to a numeric
length or precision, so a query expression can no longer place arbitrary text into the type position
of the generated SQL.

What is changed

  • A CAST expression is accepted only when its target type is one of the documented type names. A name that merely begins with a supported one, such as timestamp or int8, is now rejected as unsupported.
  • A parenthesised length or precision is accepted only as non-negative integers, so CAST(expr as char(5)) and CAST(expr as decimal(10, 2)) keep working and any other content is reported as a syntax error.
  • jsonb is a supported type name in its own right, so a cast to it is accepted and renders as it did before.
  • A type that carries a length or a precision is mapped to the platform's own type name, so CAST(expr as string(12)) produces varchar(12) on PostgreSQL and char(12) on MySQL instead of being passed through unchanged.
  • Every supported type given without a length or a precision produces the same SQL as before on both platforms.

Impact

  • Applications that rely on a platform-specific type spelling accepted only because it shares a prefix with a supported name (timestamp, timestamptz, int8) now get a syntax error and have to use one of the supported type names.
  • Queries that use the documented types, with or without a length or a precision, are unaffected, and the SQL generated for them is unchanged.
  • The dependency requirements are untouched, so a release from this branch installs alongside doctrine/orm 2.8 with doctrine/lexer 1 and doctrine/dbal 2.12, which is the combination OroPlatform 4.2 is fixed to.
  • No configuration changes or upgrade steps are required.