【发布时间】:2019-02-08 16:47:15
【问题描述】:
表格tbl列
col1 | col | col3
我想在运行时绑定参数的预处理语句使用 SQL
select col1, col2, col3
from tbl
where col1=10
and col2 between 0 and 10 and col3 like '%QUERY%';
问题在于 col3 上的过滤取决于用户输入。如果只使用 2 个术语,那么它应该是
select col1, col2, col3
from tbl
where col1=10
and col2 between 0 and 10 and (col3 like '%QUERY%' AND col3 like '%QUERY2%');
如果找到 3 个输入,那么它应该是
select col1, col2, col3
from tbl
where col1=10
and col2 between 0 and 10 and (col3 like '%QUERY%' AND col3 like '%QUERY2%' AND col3 like '%QUERY3%');
我只想使用 Prepared Statement 而不是直接查询。我知道可以通过清理输入并运行直接查询来实现同样的目的,但我仍然只喜欢准备好的语句。
如何做到这一点?
在我拥有的代码下方:( 使用开放式 SQL 注入
$terms=explode(",",$_POST['txtD']);
$sql='';
for($i=0;$i<count($terms);$i++) {
$terms[$i] = trim($terms[$i]);
if ($i!=$count-1)
$sql = $sql."`Places` LIKE '%$terms[$i]%' AND ";
else
$sql = $sql."`Places` LIKE '%$terms[$i]%'";
}
$stmt = mysqli_prepare($con,"select col1, col2, col3 from tbl where col1=? and col2 between ? and ? and ".$sql);
mysqli_stmt_bind_param($stmt,"iii", $param1, $param2, $param3);
mysqli_stmt_execute($stmt);
mysqli_stmt_close($stmt);
【问题讨论】:
-
准备 SQL 只是一个字符串。您可以构建它并将值保存在数组中以供以后用于绑定。
-
不需要括号,因为您只使用
AND子句。使用implode()这完全是微不足道的,但由于您没有展示您尝试过的内容,因此无法帮助您解决具体问题 -
如果你要在运行时绑定参数,它应该看起来像
col3 LIKE CONCAT('%', ?, '%')。 -
@MonkeyZeus 添加代码
标签: php mysql mysqli prepared-statement