php mysql 单引号,PHP的-单引号或双引号围绕SQL查询?

Is there any differences in using single quotes vs. using double quotes around a whole SQL query?

Which is better:

This approach (with single quotes):

$username = mysql_real_escape_string($username);

$password = mysql_real_escape_string($password);

$sql = 'SELECT * FROM users WHERE username = "' . $username . '" AND password = "' . $password . '" LIMIT 1';

?

Or this approach (using double quotes):

$username = mysql_real_escape_string($username);

$password = mysql_real_escape_string($password);

$sql = "SELECT * FROM users WHERE username = '{$username}' AND password = '{$password}' LIMIT 1";

Is there a better way to accomplish this?

For me I like the first approach as I always prefer single quotes in PHP. So I want to make sure that using single quotes around a whole SQL query is OK and using double quotes around variables or data is OK and is cross-platform and could be used with databases other than MySQL!

解决方案

Use PDO instead of either of these approaches. It will allow you to use parameters instead of strings.

$sth = $dbh->prepare('SELECT * FROM users WHERE username = :username AND password = :password LIMIT 1');

$sth->bindParam(':username', $username, PDO::PARAM_STR);

$sth->bindParam(':password', $password, PDO::PARAM_STR);

$sth->execute();

By the way, make sure that you're not using passwords in plain text at the same time.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值