dsa5233 2012-10-16 12:25
浏览 13
已采纳

从文本框到mysql搜索关键字

I explode the input of user to array and then search them in the database but if user enter the space as a result it will show the whole rows of the table which has space how can I make it correct?

if(isset($_POST['submit'])){
$keywords = explode(" ", $_POST["search"]);
for ($i=0; $i<count($keywords); $i++) {

$query = "SELECT * FROM mp3s " .
"WHERE (artist LIKE '%".$keywords[$i]."%' 
OR   genre LIKE '%".$keywords[$i]."%'  
OR  album LIKE '%".$keywords[$i]."%'
OR  filename LIKE '%".$keywords[$i]."%'
) ";
$sql = mysql_query($query) or die(mysql_error());

}
  • 写回答

2条回答 默认 最新

  • doubeijian2257 2012-10-16 12:35
    关注

    Use trim() to delete spaces and use mysql_real_escape_string() to prevent sql injections.

     if(isset($_POST['submit'])){
        $keywords = explode(" ", trim($_POST["search"]));
        for ($i=0; $i<count($keywords); $i++) {
    
        if(!empty($keywords[$i])) {
    
          $query = "SELECT * FROM mp3s " .
          "WHERE (artist LIKE '%".trim(mysql_real_escape_string($keywords[$i]))."%' 
          OR   genre LIKE '%".trim(mysql_real_escape_string($keywords[$i]))."%'  
          OR  album LIKE '%".trim(mysql_real_escape_string($keywords[$i]))."%'
          OR  filename LIKE '%".trim(mysql_real_escape_string($keywords[$i]))."%'
          ) ";
          $sql = mysql_query($query) or die(mysql_error());
    
        }
    
        }
    

    But it's better to use MySQLi than the mysql_real_escape_string() function.
    See http://php.net/manual/en/function.mysql-real-escape-string.php

    Or PDO with the prepared statements :
    http://php.net/manual/en/pdo.prepared-statements.php

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥50 vue组件中无法正确接收并处理axios请求
  • ¥15 隐藏系统界面pdf的打印、下载按钮
  • ¥15 MATLAB联合adams仿真卡死如何解决(代码模型无问题)
  • ¥15 基于pso参数优化的LightGBM分类模型
  • ¥15 安装Paddleocr时报错无法解决
  • ¥15 python中transformers可以正常下载,但是没有办法使用pipeline
  • ¥50 分布式追踪trace异常问题
  • ¥15 人在外地出差,速帮一点点
  • ¥15 如何使用canvas在图片上进行如下的标注,以下代码不起作用,如何修改
  • ¥50 vue router 动态路由问题