【发布时间】:2017-01-23 08:03:32
【问题描述】:
给定以下代码用于将数据插入 MySQL 以防止 SQL 注入:
$img = "http://image-generated-online/";
$description = "An image";
$sql->prepare('INSERT INTO table(img, desc) VALUES (?,?)');
$sql->bind_param("attr-for-image, s", $img, $description);
$sql->execute();
问题:
bind_param 需要一个属性类型。图像的属性类型是什么?
可能有用的信息:
数据类型在SQL表中声明为MEDIUMBLOB
【问题讨论】:
-
不要将文件保存在数据库中。 stackoverflow.com/a/41235395/267540
-
首先,bind_param 不需要属性。其次,为什么要将图像存储在数据库中,而不是仅存储在文件系统中,并在数据库中提供链接?
-
@junkfoodjunkie 因为图像是通过链接(gravatar)动态生成的。希望保存文件,但它们只是链接,除非有解决方法?
-
@junkfoodjunkie 当我删除属性类型时,我收到错误 bind_param(): Number of elements in type definition string does not match number of bind variables
-
bind_param 是一个值。您需要使用两个 bind_params,或者只在 execute() 中使用一个数组。
标签: php mysql insert sql-insert