English 中文(简体)
用于数据库查询的 is_数字($str)
原标题:is_numeric($str) for database queries

基本上,我的问题是,如果我有一个数字字符串,而且我要把它与数据库进行比较,那就是一个安全/安全的检查方法。 还是我应该像我的字符串一样逃避数字变量(像我已经做的一样)?

示例:

<?php
    $id = $_POST[ id ];
    if(is_numeric($id)){
        //database connectivity.    
    }
?>
最佳回答

“ 数据库” 相当笼统, 所以我会假设您重新使用 MySQL。 只要您在查询中插入 < code> $id < /code>, 它就安全了( 要么是用 < code> mysql_ real_ escape_ string , 要么是用准备好的语句) 。

问题回答

"从Id = 的 Tbl 选择。" (int)$_POST[id] 。"





相关问题
what is wrong with this mysql code

$db_user="root"; $db_host="localhost"; $db_password="root"; $db_name = "fayer"; $conn = mysqli_connect($db_host,$db_user,$db_password,$db_name) or die ("couldn t connect to server"); // perform query ...

Users asking for denormalized database

I am in the early stages of developing a database-driven system and the largest part of the system revolves around an inheritance type of relationship. There is a parent entity with about 10 columns ...

Easiest way to deal with sample data in Java web apps?

I m writing a Java web app in my free time to learn more about development. I m using the Stripes framework and eventually intend to use hibernate and MySQL For the moment, whilst creating the pages ...

join across databases with nhibernate

I am trying to join two tables that reside in two different databases. Every time, I try to join I get the following error: An association from the table xxx refers to an unmapped class. If the ...

How can I know if such value exists in database? (ADO.NET)

For example, I have a table, and there is a column named Tags . I want to know if value programming exists in this column. How can I do this in ADO.NET? I did this: OleDbCommand cmd = new ...

Convert date to string upon saving a doctrine record

I m trying to migrate one of my PHP projects to Doctrine. I ve never used it before so there are a few things I don t understand. In my current code, I have a class similar to this: class ...

热门标签