From 75f5331f16c8256fa27a83f6fee1c9382a9cc050 Mon Sep 17 00:00:00 2001 From: 77web Date: Tue, 29 Sep 2026 20:52:22 +0900 Subject: [PATCH 1/2] Use PHP_VERSION_ID to select Pdo\Mysql constants in Mysql::connect() Pdo\Mysql was added in PHP 8.4, not 8.1. Switch from class_exists() to a PHP_VERSION_ID >= 80400 check so the autoloader chain is not triggered on every connect() and a userland Pdo\Mysql class cannot be misdetected (same approach as CakePHP 4.x/5.x). Also route the SSL attributes through Pdo\Mysql::ATTR_SSL_* to avoid PHP 8.5 deprecations. Follow-up to https://github.com/basi/cakephp2-php8/pull/27#discussion_r4130538263 Co-Authored-By: Claude Opus 5.5 --- lib/Cake/Model/Datasource/Database/Mysql.php | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/lib/Cake/Model/Datasource/Database/Mysql.php b/lib/Cake/Model/Datasource/Database/Mysql.php index 40b8062a45..f9b7100a52 100644 --- a/lib/Cake/Model/Datasource/Database/Mysql.php +++ b/lib/Cake/Model/Datasource/Database/Mysql.php @@ -163,13 +163,19 @@ public function connect() { $config = $this->config; $this->connected = false; - // PDO::MYSQL_ATTR_* constants are deprecated in PHP 8.5; Pdo\Mysql class is available since PHP 8.1 - if (class_exists('Pdo\Mysql')) { + // PDO::MYSQL_ATTR_* constants are deprecated as of PHP 8.5 in favor of Pdo\Mysql::ATTR_* (available since PHP 8.4) + if (PHP_VERSION_ID >= 80400) { $mysqlAttrUseBufferedQuery = Pdo\Mysql::ATTR_USE_BUFFERED_QUERY; $mysqlAttrInitCommand = Pdo\Mysql::ATTR_INIT_COMMAND; + $mysqlAttrSslKey = Pdo\Mysql::ATTR_SSL_KEY; + $mysqlAttrSslCert = Pdo\Mysql::ATTR_SSL_CERT; + $mysqlAttrSslCa = Pdo\Mysql::ATTR_SSL_CA; } else { $mysqlAttrUseBufferedQuery = PDO::MYSQL_ATTR_USE_BUFFERED_QUERY; $mysqlAttrInitCommand = PDO::MYSQL_ATTR_INIT_COMMAND; + $mysqlAttrSslKey = PDO::MYSQL_ATTR_SSL_KEY; + $mysqlAttrSslCert = PDO::MYSQL_ATTR_SSL_CERT; + $mysqlAttrSslCa = PDO::MYSQL_ATTR_SSL_CA; } $flags = $config['flags'] + array( @@ -182,11 +188,11 @@ public function connect() { $flags[$mysqlAttrInitCommand] = 'SET NAMES ' . $config['encoding']; } if (!empty($config['ssl_key']) && !empty($config['ssl_cert'])) { - $flags[PDO::MYSQL_ATTR_SSL_KEY] = $config['ssl_key']; - $flags[PDO::MYSQL_ATTR_SSL_CERT] = $config['ssl_cert']; + $flags[$mysqlAttrSslKey] = $config['ssl_key']; + $flags[$mysqlAttrSslCert] = $config['ssl_cert']; } if (!empty($config['ssl_ca'])) { - $flags[PDO::MYSQL_ATTR_SSL_CA] = $config['ssl_ca']; + $flags[$mysqlAttrSslCa] = $config['ssl_ca']; } if (empty($config['unix_socket'])) { $dsn = "mysql:host={$config['host']};port={$config['port']};dbname={$config['database']}"; From 25dc516578f3fee36bcdc3975b1a4bdbe822dbaf Mon Sep 17 00:00:00 2001 From: 77web Date: Wed, 30 Sep 2026 15:11:38 +0900 Subject: [PATCH 2/2] Added changelog for PDO::MYSQL_ATTR_* deprecation fix --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index 51dff561c5..1fbb4562eb 100644 --- a/README.md +++ b/README.md @@ -59,6 +59,10 @@ It means that composer will look at `master` branch of repository configured und ## Changelog +### 2026-09-30 + +- Fix the PHP 8.5 `PDO::MYSQL_ATTR_*` deprecations in the MySQL datasource: on PHP >= 8.4, `Mysql::connect()` uses the `Pdo\Mysql::ATTR_*` constants, including the SSL ones (based on kamilwylegala/cakephp2-php8#86). Apps passing `PDO::MYSQL_ATTR_*` in the datasource `flags` option should switch to `Pdo\Mysql::ATTR_*` on PHP >= 8.4 as well. + ### 2026-08-26 - Security: backported the view template path containment check from CakePHP 4.5.11 (CVE-2026-48820 / GHSA-wpvj-hjcr-h3p2). Element / view / layout names resolving outside the configured view template paths now throw `InvalidArgumentException`. BC note: `elementExists()` now throws for such names instead of returning `false`.