ÉèΪÊ×Ò³ ¼ÓÈëÊÕ²Ø

TOP

³õ̽PHPµÄSQL×¢Èë¹¥»÷µÄ¼¼ÊõʵÏÖÒÔ¼°Ô¤·À´ëÊ©(¶þ)
2014-11-24 07:22:23 À´Ô´: ×÷Õß: ¡¾´ó ÖРС¡¿ ä¯ÀÀ:6´Î
Tags£º³õ̽ PHP SQL ×¢Èë ¹¥»÷ ¼¼Êõ ʵÏÖ ÒÔ¼° Ô¤·À´ëÊ©
MIT 0,1 ¹¥»÷Õß´ïµ½ÁËÄ¿µÄ¡£

\

Èý¡¢ÈçºÎ·ÀÖ¹ PHPµÄSQL ×¢Èë¹¥»÷

ÈçºÎ·ÀÖ¹ php sql ×¢Èë¹¥»÷£¿ÎÒÈÏΪ×îÖØÒªµÄÒ»µã£¬¾ÍÊÇÒª¶ÔÊý¾ÝÀàÐͽøÐмì²éºÍתÒå¡£×ܽáµÄ¼¸µã¹æÔòÈçÏ£º

1. php.ini ÖÐµÄ display_errors Ñ¡ÏӦ¸ÃÉèΪ¡¡display_errors = off¡£ÕâÑù php ½Å±¾³ö´íÖ®ºó£¬²»»áÔÚ web Ò³ÃæÊä³ö´íÎó£¬ÒÔÃâÈù¥»÷Õß·ÖÎö³öÓÐ×÷µÄÐÅÏ¢¡£

2. µ÷Óà mysql_query µÈ mysql º¯Êýʱ£¬Ç°ÃæÓ¦¸Ã¼ÓÉÏ @£¬¼´ @mysql_query(...)£¬ÕâÑù mysql ´íÎ󲻻ᱻÊä³ö¡£Í¬ÀíÒÔÃâÈù¥»÷Õß·ÖÎö³öÓÐÓõÄÐÅÏ¢¡£ÁíÍ⣬ÓÐЩ³ÌÐòÔ±ÔÚ×ö¿ª·¢Ê±£¬µ± mysql_query³ö´íʱ£¬Ï°¹ßÊä³ö´íÎóÒÔ¼° sql Óï¾ä£¬ÀýÈ磺


ÕâÖÖ×ö·¨ÊÇÏ൱ΣÏÕºÍÓÞ´ÀµÄ¡£Èç¹ûÒ»¶¨ÒªÕâô×ö£¬×îºÃÔÚÍøÕ¾µÄÅäÖÃÎļþÖУ¬ÉèÒ»¸öÈ«¾Ö±äÁ¿»ò¶¨ÒåÒ»¸öºê£¬ÉèһϠdebug ±êÖ¾£º

< php
//È«¾ÖÅäÖÃÎļþÖУº
define("DEBUG_MODE", 0);    // 1: DEBUG MODE; 0: RELEASE MODE
//µ÷Óýű¾ÖУº
$t_strSQL = "SELECT a from b....";
if (mysql_query($t_strSQL)) {
    // ÕýÈ·µÄ´¦Àí
} else {
    if (DEBUG_MODE) {
        echo "´íÎó! SQL Óï¾ä£º$t_strSQL´íÎóÐÅÏ¢" . mysql_query();
    }
    exit;
}
 >

3. ¶ÔÌá½»µÄ sql Óï¾ä£¬½øÐÐתÒåºÍÀàÐͼì²é¡£

ËÄ¡¢ÎÒдµÄÒ»¸ö°²È«²ÎÊý»ñÈ¡º¯Êý

ΪÁË·ÀÖ¹Óû§µÄ´íÎóÊý¾ÝºÍ php + mysql ×¢Èë £¬ÎÒдÁËÒ»¸öº¯Êý PAPI_GetSafeParam()£¬ÓÃÀ´»ñÈ¡°²È«µÄ²ÎÊýÖµ£º

< php
define("XH_PARAM_INT", 0);
define("XH_PARAM_TXT", 1);
function PAPI_GetSafeParam($pi_strName, $pi_Def = "", $pi_iType = XH_PARAM_TXT) {
    if (isset($_GET[$pi_strName])) {
        $t_Val = trim($_GET[$pi_strName]);
    } else if (isset($_POST[$pi_strName])) {
        $t_Val = trim($_POST[$pi_strName]);
    } else {
        return $pi_Def;
    }

    // INT
    if (XH_PARAM_INT == $pi_iType) {
        if (is_numeric($t_Val)) {
            return $t_Val;
        } else {
            return $pi_Def;
        }
    }
 
    // String
    $t_Val = str_replace("&", "&", $t_Val);
    $t_Val = str_replace("<", "<", $t_Val);
    $t_Val = str_replace(">", ">", $t_Val);
 
    if (get_magic_quotes_gpc()) {
        $t_Val = str_replace("\"", """, $t_Val);
        $t_Val = str_replace("\''", "'", $t_Val);
    } else {
        $t_Val = str_replace(""", """, $t_Val);
        $t_Val = str_replace("'", "'", $t_Val);
    }
 
    return $t_Val;
}
 >

ÔÚÕâ¸öº¯ÊýÖУ¬ÓÐÈý¸ö²ÎÊý£º

  • $pi_strName£º±äÁ¿Ãû
  • $pi_Def£ºÄ¬ÈÏÖµ
  • $pi_iType£º Êý¾ÝÀàÐÍ¡£È¡ÖµÎª XH_PARAM_INT£¬XH_PARAM_TXT£¬·Ö±ð±íʾÊýÖµÐͺÍÎı¾ÐÍ¡£

    Èç¹ûÇëÇóÊÇÊýÖµÐÍ£¬ÄÇôµ÷Óà is_numeric() ÅжÏÊÇ·ñΪÊýÖµ¡£Èç¹û²»ÊÇ£¬Ôò·µ»Ø³ÌÐòÖ¸¶¨µÄĬÈÏÖµ¡£

    ¼òµ¥Æð¼û£¬¶ÔÓÚÎı¾´®£¬ÎÒ½«Óû§ÊäÈëµÄËùÓÐΣÏÕ×Ö·û£¨°üÀ¨HTML´úÂ룩£¬È«²¿×ªÒå¡£ÓÉÓÚ php º¯Êý addslashes()´æÔÚ©¶´£¬ÎÒÓà str_replace()Ö±½ÓÌæ»»¡£get_magic_quotes_gpc( ) º¯ÊýÊÇ php µÄº¯Êý£¬ÓÃÀ´ÅÐ¶Ï magic_quotes_gpc Ñ¡ÏîÊÇ·ñ´ò¿ª¡£

    ¸Õ²ÅµÚ¶þ½ÚµÄʾÀý£¬´úÂë¿ÉÒÔÕâÑùµ÷Óãº

    < php
    if (isset($_POST["f_login"])) {
        // Á¬½ÓÊý¾Ý¿â...
        // ...´úÂëÂÔ...
        // ¼ì²éÓû§ÊÇ·ñ´æÔÚ
        $t_strUid = PAPI_GetSafeParam("f_uid", 0, XH_PARAM_INT);
        $t_strPwd = PAPI_GetSafeParam("f_pwd", "", XH_PARAM_TXT);
        $t_strSQL = "SELECT * FROM tbl_users WHERE uid=$t_strUid AND password = '$t_strPwd' LIMIT 0,1";
        if ($t_hRes = mysql_query($t_strSQL)) {
            // ³É¹¦²éѯ֮ºóµÄ´¦Àí. ÂÔ...
        }
    }
     >

    ÕâÑùµÄ»°£¬¾ÍÒѾ­Ï൱°²È«ÁË¡£PAPI_GetSafeParamµÄ´úÂëÓе㳤£¬µ«ÎþÉüÕâµãЧÂÊ£¬¶Ô±£Ö¤°²È«£¬ÊÇÖµµÃµÄ¡£Ï£Íû´ó¼Ò¶àÅúÆÀÖ¸Õý¡£

    \

Ê×Ò³ ÉÏÒ»Ò³ 1 2 ÏÂÒ»Ò³ βҳ 2/2/2
¡¾´ó ÖРС¡¿¡¾´òÓ¡¡¿ ¡¾·±Ìå¡¿¡¾Í¶¸å¡¿¡¾Êղء¿ ¡¾ÍƼö¡¿¡¾¾Ù±¨¡¿¡¾ÆÀÂÛ¡¿ ¡¾¹Ø±Õ¡¿ ¡¾·µ»Ø¶¥²¿¡¿
·ÖÏíµ½: 
ÉÏһƪ£ºÍ¼Æ¬ÉÏ´«µ½SQLServer ÏÂһƪ£ºÈ¥µôÏ»®Ïß²¢×ªÊ××ÖĸΪ´óд

ÆÀÂÛ

ÕÊ¡¡¡¡ºÅ: ÃÜÂë: (ÐÂÓû§×¢²á)
Ñé Ö¤ Âë:
±í¡¡¡¡Çé:
ÄÚ¡¡¡¡ÈÝ:

¡¤Linuxϵͳ¼ò½é (2025-12-25 21:55:25)
¡¤Linux°²×°MySQL¹ý³Ì (2025-12-25 21:55:22)
¡¤Linuxϵͳ°²×°½Ì³Ì£¨ (2025-12-25 21:55:20)
¡¤HTTP Åc HTTPS µÄ²î„ (2025-12-25 21:19:45)
¡¤ÍøÕ¾°²È«±ØÐ޿ΣºÍ¼ (2025-12-25 21:19:42)