Quoting and Placeholder Support
2.10.8 Quoting and Placeholder Support
I n Recipe 2.9 , we developed a PHP sql_quote funct ion for PHP t o handle quot ing, escaping, and NULL unset values, so t hat any value can be insert ed easily int o a query: function sql_quote str { if isset str return NULL; func = function_exists mysql_escape_string ? mysql_escape_string : addslashes; return . func str . ; } I f w e add sql_quote t o t he MySQL_Access class, it becom es available aut om at ically t o any class inst ance as an obj ect m et hod and you can const ruct query st rings t hat include properly quot ed values like so: stmt = sprintf INSERT INTO profile name,birth,color,foods,cats VALUESs,s,s,s,s, conn-sql_quote DeMont, conn-sql_quote 1973-01-12, conn-sql_quote NULL, conn-sql_quote eggroll, conn-sql_quote 4; conn-issue_query stmt; I n fact , we can em ploy t he sql_quote m et hod as t he basis for a placeholder em ulat ion m echanism , t o be used as follows: 1. Begin by passing a quer y st r ing t o t he prepare_query m et hod. 2. I ndicat e placeholder s in t he quer y st r ing by using ? char act er s. 3. Execut e t he query and supply an array of values t o be bound t o t he query, one value per placeholder. To bind NULL t o a placeholder , pass t he PHP NULL v alue. One way t o perform param et er binding is t o do a lot of pat t ern m at ching and subst it ut ion in t he query st ring wherever ? occurs as a placeholder charact er. An easier approach is sim ply t o break t he query st ring at t he ? charact ers, t hen glue t he pieces back t oget her at query execut ion t im e wit h t he properly quot ed dat a values insert ed bet ween t he pieces. Split t ing t he query also is an easy way t o find out how m any placeholders t here are it s t he num ber of pieces, m inus one . That s useful for det erm ining whet her or not t he proper num ber of dat a values is present when it com es t im e t o bind t hose values t o t he placeholders. The prepare_query m et hod is quit e sim ple. All it does is split up t he query st ring at ? charact ers, placing t he result int o t he query_pieces array for lat er use at param et er- binding t im e: function prepare_query query { this-query_pieces = explode ?, query; return TRUE; } We could invent new calls for binding dat a values t o t he query and for execut ing it , but it s also possible t o m odify issue_query a lit t le, t o have it det erm ine what t o do by exam ining t he t ype of it s argum ent . I f t he argum ent is a st ring, it s int erpret ed as a query t hat should be execut ed direct ly which is how issue_query behaved before . I f t he argum ent is an array, it is assum ed t o cont ain dat a values t o be bound t o a previously prepared st at em ent . Wit h t his change, issue_query looks like t his: function issue_query arg = { if arg == if no argument, assume prepared statement arg = array ; with no values to be bound if this-connect establish connection to server if return FALSE; necessary if is_string arg arg is a simple query query_str = arg; else if is_array arg arg contains data values for placeholders { if count arg = count this-query_pieces - 1 { this-errno = -1; this-errstr = data valueplaceholder count mismatch; this-error Cannot execute query; return FALSE; } insert data values into query at placeholder positions, quoting values as we go query_str = this-query_pieces[0]; for i = 0; i count arg; i++ { query_str .= this-sql_quote arg[i] . this-query_pieces[i+1]; } } else arg is garbage { this-errno = -1; this-errstr = unknown argument type to issue_query; this-error Cannot execute query; return FALSE; } this-num_rows = 0; this-result_id = mysql_query query_str, this-conn_id; this-errno = mysql_errno ; this-errstr = mysql_error ; if this-errno { this-error Cannot execute query: query_str; return FALSE; } get number of affected rows for non-SELECT; this also returns number of rows for a SELECT this-num_rows = mysql_affected_rows this-conn_id; return this-result_id; } Now t hat quot ing and placeholder support is in place, t he class provides t hree ways of issuing queries. First , you can writ e out t he ent ire query st ring lit erally and perform quot ing, escaping, and NULL handling yourself: conn-issue_query INSERT INTO profile name,birth,color,foods,cats VALUESDe\Mont,1973-01-12,NULL,eggroll,4; Second, you can use t he sql_quote m et hod t o insert dat a values int o t he query st ring: stmt = sprintf INSERT INTO profile name,birth,color,foods,cats VALUESs,s,s,s,s, conn-sql_quote DeMont, conn-sql_quote 1973-01-12, conn-sql_quote NULL, conn-sql_quote eggroll, conn-sql_quote 4; conn-issue_query stmt; Third, you can use placeholders and let t he class int erface handle all t he work of binding values t o t he query: conn-prepare_query INSERT INTO profile name,birth,color,foods,cats VALUES?,?,?,?,?; conn-issue_query array DeMont, 1973-01-12, NULL, eggroll, 4; The MySQL_Access and Cookbook_DB_Access classes now provide a reasonably convenient m eans of writ ing PHP script s t hat is easier t o use t han t he nat ive MySQL PHP calls. The class int erface also includes placeholder support , som et hing t hat PHP does not provide at all. The developm ent of t hese classes illust rat es how you can writ e your own int erface t hat hides MySQL-specific det ails. The int erface is not wit hout it s short com ings, nat urally. For exam ple, it allow s you t o prepare only one st at em ent at a t im e, unlike DBI and JDBC, which support m ult iple sim ult aneous prepared st at em ent s. Should you require such funct ionalit y, you m ight consider how t o reim plem ent MySQL_Access t o provide it .2.11 Ways of Obtaining Connection Parameters
Parts
» O'Reilly-MySQL.Cookbook.eBook-iNTENSiTY. 4810KB Mar 29 2010 05:03:43 AM
» Introduction Using the mysql Client Program
» Problem Solution Discussion Setting Up a MySQL User Account
» Problem Solution Discussion Starting and Terminating mysql
» Problem Solution Discussion Specifying Connection Parameters by Using Option Files
» Problem Solution Discussion Mixing Command-Line and Option File Parameters
» Problem Solution Discussion What to Do if mysql Cannot Be Found
» Problem Solution Discussion Setting Environment Variables
» Problem Solution Discussion Repeating and Editing Queries
» Problem Solution Discussion Preventing Query Output from Scrolling off the Screen
» Problem Solution Discussion Specifying Arbitrary Output Column Delimiters
» Problem Solution Discussion Logging Interactive mysql Sessions
» Discussion Using mysql as a Calculator
» Writing Shell Scripts Under Unix
» Writing Shell Scripts Under Windows
» MySQL Client Application Programming Interfaces
» Perl Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» PHP Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Python Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Java Connecting to the MySQL Server, Selecting a Database, and Disconnecting
» Problem Solution Discussion Checking for Errors
» Python Java Checking for Errors
» Problem Solution Discussion Writing Library Files
» Python Writing Library Files
» SQL Statement Categories Issuing Queries and Retrieving Results
» Perl Issuing Queries and Retrieving Results
» Python Issuing Queries and Retrieving Results
» Java Issuing Queries and Retrieving Results
» Problem Solution Discussion Moving Around Within a Result Set
» Problem Solution Discussion Using Prepared Statements and Placeholders in Queries
» Perl Using Prepared Statements and Placeholders in Queries
» PHP Python Java Using Prepared Statements and Placeholders in Queries
» Problem Solution Discussion Including Special Characters and NULL Values in Queries
» Perl Including Special Characters and NULL Values in Queries
» PHP Including Special Characters and NULL Values in Queries
» Python Java Including Special Characters and NULL Values in Queries
» PHP Python Java Handling NULL Values in Result Sets
» Problem Solution Discussion Writing an Object-Oriented MySQL Interface for PHP
» Class Overview Writing an Object-Oriented MySQL Interface for PHP
» Connecting and Disconnecting Writing an Object-Oriented MySQL Interface for PHP
» Error Handling Issuing Queries and Processing the Results
» Quoting and Placeholder Support
» Problem Solution Discussion Ways of Obtaining Connection Parameters
» Getting Parameters from the Command Line
» Getting Parameters from Option Files
» Conclusion and Words of Advice
» Problem Solution Discussion Avoiding Output Column Order Problems When Writing Programs
» Problem Solution Discussion Using Column Aliases to Make Programs Easier to Write
» Problem Solution Discussion Selecting a Result Set into an Existing Table
» Problem Solution Discussion Creating a Destination Table on the Fly from a Result Set
» Problem Solution Discussion Moving Records Between Tables Safely
» Problem Solution Discussion Cloning a Table Exactly
» Problem Solution Discussion Generating Unique Table Names
» Problem Solution Discussion Using TIMESTAMP Values
» Problem Solution Discussion Using ORDER BY to Sort Query Results
» Solution Discussion Working with Per-Group and Overall Summary Values Simultaneously
» Problem Solution Discussion Changing a Column Definition or Name
» Problem Solution Discussion Changing a Table Type
» Problem Solution Discussion Adding Indexes
» Introduction Obtaining and Using Metadata
» Problem Solution Discussion Perl PHP
» Problem Solution Discussion Perl
» PHP Obtaining Result Set Metadata
» Python Obtaining Result Set Metadata
» Java Obtaining Result Set Metadata
» Using Result Set Metadata to Get Table Structure
» Problem Solution Discussion Database-Independent Methods of Obtaining Table Information
» Problem Solution Discussion Displaying Column Lists Interactive Record Editing
» Mapping Column Types onto Web Page Elements Adding Elements to ENUM or SET Column Definitions
» Selecting All Except Certain Columns
» Problem Solution Discussion Listing Tables and Databases
» Problem Solution Writing Applications That Adapt to the MySQL Server Version
» Discussion Writing Applications That Adapt to the MySQL Server Version
» Problem Solution Discussion Determining Which Table Types the Server Supports
» General Import and Export Issues
» Problem Solution Discussion Importing Data with LOAD DATA and mysqlimport
» Problem Solution Discussion Specifying the Datafile Location
» Problem Solution Discussion Specifying the Datafile Format
» Problem Solution Discussion Dealing with Quotes and Special Characters
» Problem Solution Discussion Handling Duplicate Index Values
» Problem Solution Discussion Getting LOAD DATA to Cough Up More Information
» Problem Solution Discussion Dont Assume LOAD DATA Knows More than It Does
» Problem Solution Discussion Skipping Datafile Columns
» Problem Solution Discussion Exporting Query Results from MySQL
» Using the mysql Client to Export Data
» Problem Solution Discussion Exporting Tables as Raw Data
» Problem Solution Discussion Exporting Table Contents or Definitions in SQL Format
» Problem Solution Discussion Copying Tables or Databases to Another Server
» Problem Solution Discussion Writing Your Own Export Programs
» Problem Solution Discussion Converting Datafiles from One Format to Another
» Problem Solution Discussion Extracting and Rearranging Datafile Columns
» Problem Solution Discussion Validating and Transforming Data
» Writing an Input-Processing Loop Putting Common Tests in Libraries
» Problem Solution Discussion Validation by Pattern Matching
» Problem Solution Discussion Using Patterns to Match Numeric Values
» Problem Solution Discussion Using Patterns to Match Dates or Times
» See Also Using Patterns to Match Dates or Times
» Problem Solution Discussion Using Patterns to Match Email Addresses and URLs
» Problem Solution Discussion Validation Using Table Metadata
» Problem Solution Discussion Issue Individual Queries Construct a Hash from the Entire Lookup Table
» Use a Hash as a Cache of Already-Seen Lookup Values
» Problem Solution Discussion Converting Two-Digit Year Values to Four-Digit Form
» Problem Solution Discussion Performing Validity Checking on Date or Time Subparts
» Problem Solution Discussion Writing Date-Processing Utilities
» Problem Solution Discussion Performing Date Conversion Using SQL
» Problem Solution Discussion Guessing Table Structure from a Datafile
» Problem Solution Discussion A LOAD DATA Diagnostic Utility
» Problem Solution Discussion Exchanging Data Between MySQL and Microsoft Access
» Problem Solution Discussion Exchanging Data Between MySQL and Microsoft Excel
» Problem Solution Discussion Exchanging Data Between MySQL and FileMaker Pro
» Problem Solution Discussion Importing XML into MySQL
» Epilog Importing and Exporting Data
» Introduction Generating and Using Sequences
» Problem Solution Discussion Using AUTO_INCREMENT To Set Up a Sequence Column
» Problem Solution Discussion Choosing the Type for a Sequence Column
» Problem Solution Discussion Ensuring That Rows Are Renumbered in a Particular Order
» Problem Solution Discussion Managing Multiple Simultaneous AUTO_INCREMENT Values
» Problem Solution Discussion Using AUTO_INCREMENT Values to Relate Tables
» Problem Solution Discussion Generating Repeating Sequences
» Problem Solution Discussion See Also
» Performing a Related-Table Update Using Table Replacement
» Performing a Related-Table Update by Writing a Program
» Performing a Multiple-Table Delete by Writing a Program
» Problem Solution Discussion Dealing with Duplicates at Record-Creation Time
» Problem Solution Discussion Using Transactions in Perl Programs
» Problem Solution Discussion Using Transactions in Java Programs
» Problem Solution Discussion Using Alternatives to Transactions
» Grouping Statements Using Locks
» Rewriting Queries to Avoid Transactions
» Introduction Introduction to MySQL on the Web
» Problem Solution Discussion Basic Web Page Generation
» Problem Solution Discussion Using Apache to Run Web Scripts
» Problem Solution Discussion Using Tomcat to Run Web Scripts
» Installing the mcb Application
» Installing the JSTL Distribution
» Problem Solution Discussion Encoding Special Characters in Web Output
» General Encoding Principles Encoding Special Characters in Web Output
» Encoding Special Characters Using Web APIs
» Introduction Incorporating Query Results into Web Pages
» Problem Solution Discussion Creating a Navigation Index from Database Content
» Creating a Multiple-Page Navigation Index
» Problem Solution Discussion Storing Images or Other Binary Data
» Storing Images with LOAD_FILE Storing Images Using a Script
» Problem Solution Discussion Retrieving Images or Other Binary Data
» Problem Solution Discussion Serving Banner Ads
» Problem Solution Discussion Serving Query Results for Download
» Introduction Processing Web Input with MySQL
» Problem Solution Discussion Creating Forms in Scripts
» Problem Solution Discussion Creating Multiple-Pick Form Elements from Database Content
» Problem Solution Discussion Loading a Database Record into a Form
» Problem Solution Discussion Collecting Web Input
» Web Input Extraction Conventions Perl
» Problem Solution Discussion Validating Web Input
» Problem Solution Discussion Using Web Input to Construct Queries
» Problem Solution Discussion Processing File Uploads
» Perl Processing File Uploads
» Problem Solution Discussion Performing Searches and Presenting the Results
» Problem Solution Discussion Generating Previous-Page and Next-Page Links
» Paged Displays with Previous-Page and Next-Page Links
» Paged Displays with Links to Each Page
» Problem Solution Discussion Web Page Access Counting
» Problem Solution Discussion Web Page Access Logging
» Problem Solution Discussion Setting Up Database Logging
» Other Logging Issues Using MySQL for Apache Logging
» Session Management Issues Introduction
» Problem Solution Discussion Installing Apache::Session
» The Apache::Session Interface
» A Sample Application Using MySQL-Based Sessions in Perl Applications
» Problem Solution Discussion The PHP 4 Session Management Interface
» Specifying a User-Defined Storage Module
» Problem Solution Discussion Using MySQL for Session BackingStore with Tomcat
» The Servlet and JSP Session Interface A Sample JSP Session Application
Show more