请问如何使这个查询sql注入安全?JRequest::getVar 会确保传递的参数是 sql 注入安全的吗?
$product_id = JRequest::getVar('product_id')
$db = JFactory::getDBO();
$query = " select * from #__products where product_id=".$product_id."; ";
$db->setQuery($query);
$data = $db->loadObjectList();
return $data[0];