dongza6247 2014-09-26 08:24
浏览 67
已采纳

Postgres,查询错误

I do one query and I have syntax error. But for me I do all right.

Where I have error?

Thanks!

$str = "Moscow";
$data = $ci->crud_model->query(
    'select * from "Cities" where  "defaultName" ilike  %'.$str.'%'
);

Query is : select * from "Cities" where "defaultName" ilike %Moscow%

  • 写回答

3条回答 默认 最新

  • douzhanyan5015 2014-09-26 08:53
    关注

    The LIKE/ILIKE operator takes two strings as its arguments. That is, the pattern has to be a quoted string, not just directly in the SQL query.

    So instead of:

    "defaultName" ilike %Moscow%
    

    You need:

    "defaultName" ilike '%Moscow%'
    

    In PHP, you should be (at the very least) escaping the input to avoid SQL Injection. Probably CodeIgniter has facilities for escaping, or using parameterised queries, but at the very least you should do this:

    $str = "Moscow";
    $data = $ci->crud_model->query(
        'select * from "Cities" where  "defaultName" ilike  \'%'.pg_escape_string($str).'%\''
    );
    

    EDIT Per Craig Ringer's comment, the correct ways to escape or build safe queries with CodeIgniter are covered in this answer.

    This is probably the simplest (note that the query parameter is automatically a string, and doesn't need extra quotes):

    $str = "Moscow";
    $data = $ci->crud_model->query(
        'select * from "Cities" where  "defaultName" ilike ?',
        array('%' . $str . '%')
    );
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 请问为什么我配置IPsec后PC1 ping不通 PC2,抓包出来数据包也并没有被加密
  • ¥200 求博主教我搞定neo4j简易问答系统,有偿
  • ¥15 nginx的使用与作用
  • ¥100 关于#VijeoCitect#的问题,如何解决?(标签-ar|关键词-数据类型)
  • ¥15 一个矿井排水监控系统的plc梯形图,求各程序段都是什么意思
  • ¥15 ensp路由器启动不了一直报#
  • ¥50 安卓10如何在没有root权限的情况下设置开机自动启动指定app?
  • ¥15 ats2837 spi2从机的代码
  • ¥200 wsl2 vllm qwen1.5部署问题
  • ¥100 有偿求数字经济对经贸的影响机制的一个数学模型,弄不出来已经快要碎掉了