【发布时间】:2016-01-31 19:42:37
【问题描述】:
我有一个带有日期的 HTML 表单
<input type="date" name="mydate">
我的 PHP 脚本在表单提交时启动。它或多或少看起来像这样:
$mydate = $_POST['mydate'];
$query = "insert into datetable(when) values({$mydate})";
$res = pg_query($db, $query);
它只是不起作用。当我尝试在我的 psql CLI 中手动运行生成查询时,我收到如下错误:
ERROR: column "when" is of type date but expression is of type integer LINE 1: ..., when) values (1990-01-01... ^ HINT: You will need to rewrite or cast the expression.
但是我不知道该怎么做。
我尝试在 PHP 中使用 date() 和 timetostr 转换 mydate。我也试过用to_char(), to_date() 做点什么。但是我仍然无法做任何事情来让它运行......
【问题讨论】:
-
您应该阅读有关 SQL 注入的内容。
-
使用
pg_query_params或添加撇号。
标签: php forms postgresql date sql-insert