mysql的程序怎么升级成mysqli,如何从mysql_ *升级到mysqli_ *?

I'm currently using deprecated code to get data from users, as follows:

/* retrieve */

$lastName = $_POST['lastName'];

$firstName = $_POST['firstName'];

$examLevel=$_POST['level'];

/* connect */

$dbc=mysql_connect("localhost", "user", "passw") or die('Error connecting to MySQL server');

mysql_select_db("db") or die('Error selecting database.');

/* sanitize */

$lastName=mysql_real_escape_string($lastName);

$firstName=mysql_real_escape_string($firstName);

$examLevel=mysql_real_escape_string($examLevel);

/* insert */

$query_personal = "INSERT INTO personal (LastName, FirstName) VALUES ('$lastName', '$firstName')";

$query_exam = "INSERT INTO exam (Level, Centre, BackupCentre, etc.) VALUES ('$examLevel', '$centre', '$backup', 'etc')";

This is working but I keep coming across warnings about security and lack of support. There's a small rewrite to connect with mysqli instead of mysql but what about mysqli_real_escape_string? I've seen it used in examples but I've also seen advice to use prepared statements instead which don't use mysqli_real_escape_string.

And how would I use prepared statements to INSERT my data? I'm a bit at sea with this bit so far. For example, is parameter binding only for INSERTs and result binding only for SELECTs?

解决方案

Convert it to PDO

/* connect */

$dsn = "mysql:host=localhost;db=test;charset=utf8";

$opt = array(

PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,

PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC

);

$pdo = new PDO($dsn,"user", "passw", $opt);

/* insert */

$query = "INSERT INTO personal (LastName, FirstName) VALUES (?, ?)";

$stmt = $pdo->prepare($query);

$stmt->execute(array($_POST['lastName'],$_POST['firstName']));

$query = "INSERT INTO exam (Level, Centre, BackupCentre, etc) VALUES (?, ?, ?, 'etc')";

$stmt = $pdo->prepare($query);

$stmt->execute(array($_POST['level'], $centre, $backup));

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值