douyue3800 2019-03-28 04:03
浏览 123
已采纳

如何在HEREDOC SQL查询中使用PHP变量?

I am trying to perform a SQL query in PHP using HEREDOC form. While the single-line form works properly, the same kind of thing does not work in the HEREDOC form.

This is the HEREDOC code I am attempting to use:

$sql = <<<SQL
    SELECT *
    FROM `users`, `passwords`
    WHERE users.User_id = passwords.User_id 
    AND {$formusername} = users.User_name
    AND {$formpassword} = passwords.User_password
SQL;

The above statement returns 0 rows when I know that the values I supply through my form should yield at least 1 row. Further, I know that the issue is in the AND statements because removing them yields rows. I suspect that it's the way I am writing the variables in the statement that is causing the issue.

The below syntax works properly:

$sql = 'SELECT * FROM users, passwords WHERE users.User_id = passwords.User_id AND "'.$formusername.'" = users.User_name AND "'.$formpassword.'" = passwords.User_password';

1 row is correctly returned for the values I supply through the HTML5 form.

What is wrong with my HEREDOC syntax?

Edit: I know that I should use prepared statements to avoid SQL injection. This is just a small example for class and I need the HEREDOC form to work.

  • 写回答

1条回答 默认 最新

  • dongtan5558 2019-03-28 04:31
    关注

    Try this:

    $sql = <<<SQL
        SELECT *
        FROM `users`, `passwords`
        WHERE users.User_id = passwords.User_id 
        AND "{$formusername}" = users.User_name
        AND "{$formpassword}" = passwords.User_password
    SQL;
    

    The issue is the missing quotes(") in the variables, like just {$formusername} instead of "{$formusername}". Hope that fixes the issue.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥30 帮我写一段可以读取LD2450数据并计算距离的Arduino代码
  • ¥15 C#调用python代码(python带有库)
  • ¥15 矩阵加法的规则是两个矩阵中对应位置的数的绝对值进行加和
  • ¥15 活动选择题。最多可以参加几个项目?
  • ¥15 飞机曲面部件如机翼,壁板等具体的孔位模型
  • ¥15 vs2019中数据导出问题
  • ¥20 云服务Linux系统TCP-MSS值修改?
  • ¥20 关于#单片机#的问题:项目:使用模拟iic与ov2640通讯环境:F407问题:读取的ID号总是0xff,自己调了调发现在读从机数据时,SDA线上并未有信号变化(语言-c语言)
  • ¥20 怎么在stm32门禁成品上增加查询记录功能
  • ¥15 Source insight编写代码后使用CCS5.2版本import之后,代码跳到注释行里面