我有一个页面,其中有多个简单的输入供用户选择信息更新选项。用户可能尚未定义更新配置文件,因此我尝试使用“INSERT INTO ... ON DUPLICATE KEY UPDATE”语句。我也在尝试使用 sprintf 来避免可能的 SQL 注入问题。我的问题是我无法开始弄清楚如何编写 SQL 语句。这是代码的相关部分。
$updateSQL = sprintf("INSERT INTO reminders_cfg
(id, day_of, day_of_advance, day_prior, default_time, week_prior, 2_week_prior, 3_week_prior, 4_week_prior, 5_week_prior, day_after, 2_week_after, 50_day_after)
VALUES %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s
ON DUPLICATE KEY UPDATE ",
GetSQLValueString($jeweler, "text"),
GetSQLValueString($_POST['DayOf'], "text"),
GetSQLValueString($_POST['Advance'], "text"),
GetSQLValueString($_POST['DayPrior'], "text"),
GetSQLValueString($_POST['Time'], "text"),
GetSQLValueString($_POST['WeekPrior'], "text"),
GetSQLValueString($_POST['2WeeksPrior'], "text"),
GetSQLValueString($_POST['3WeeksPrior'], "text"),
GetSQLValueString($_POST['4WeeksPrior'], "text"),
GetSQLValueString($_POST['5WeeksPrior'], "text"),
GetSQLValueString($_POST['DayAfter'], "text"),
GetSQLValueString($_POST['2WeeksAfter'], "text"),
GetSQLValueString($_POST['50DaysAfter'], "text"));
这是在 Dreamweaver 中完成的 PHP 页面。这就是 GetSQLValueString 函数的用武之地。我真的不知道在实际的“ON DUPLICATE KEY UPDATE”部分之后要做什么,以便不必再次复制所有变量和占位符。我希望这是有道理的。
更新:好的。这是我最新的尝试,但仍然无法正常工作。
if ((isset($_POST["MM_update"])) && ($_POST["MM_update"] == "form1")) {
$stmt = $mysqli->prepare("INSERT INTO reminders_cfg
(id, day_of, day_of_advance, day_prior, default_time, week_prior, 2_week_prior, 3_week_prior, 4_week_prior, 5_week_prior, day_after, 2_week_after, 50_day_after)
VALUES :id, :day_of, :day_of_advance, :day_prior, :default_time, :week_prior, :2_week_prior, :3_week_prior, :4_week_prior, :5_week_prior, :day_after, :2_week_after, :50_day_after
ON DUPLICATE KEY UPDATE day_of = :day_of, day_of_advance = :day_of_advance, day_prior = :day_prior, default_time = :default_time, week_prior = :Week_prior, 2_week_prior = :2_week_prior, 3_week_prior = :3_week_prior, 4_week_prior = :4_week_prior, 5_week_prior = :5_week_prior, day_after = :day_after, 2_week_after = :2_week_after, 50_day_after = :50_day_after")
or die($mysqli->error);
$stmt->bindParam(':id', $jeweler, PDO::PARAM_INT);
$stmt->bindParam(':day_of', $_POST['DayOf'], PDO::PARAM_STR, 6);
$stmt->bindParam(':day_of_advance', $_POST['Advance'], PDO::PARAM_INT);
$stmt->bindParam(':day_prior', $_POST['DayPrior'], PDO::PARAM_STR, 6);
$stmt->bindParam(':default_time', $_POST['Time'], PDO::PARAM_STR, 9);
$stmt->bindParam(':week_prior', $_POST['WeekPrior'], PDO::PARAM_STR, 6);
$stmt->bindParam(':2_week_prior', $_POST['2WeeksPrior'], PDO::PARAM_STR, 6);
$stmt->bindParam(':3_week_prior', $_POST['3WeeksPrior'], PDO::PARAM_STR, 6);
$stmt->bindParam(':4_week_prior', $_POST['4WeeksPrior'], PDO::PARAM_STR, 6);
$stmt->bindParam(':5_week_prior', $_POST['5WeeksPrior'], PDO::PARAM_STR, 6);
$stmt->bindParam(':day_after', $_POST['DayAfter'], PDO::PARAM_STR, 6);
$stmt->bindParam(':2_week_after', $_POST['2WeeksAfter'], PDO::PARAM_STR, 6);
$stmt->bindParam(':50_day_after', $_POST['50DaysAfter'], PDO::PARAM_STR, 6);
$stmt->execute() or die("Insert query error: " . mysql_error());
$stmt->close();
}
这会产生一个 SQL 语法错误,因为我对这个“插入到......在重复密钥更新”上是新手,所以我有点卡住了。这是错误...
您的 SQL 语法有错误;检查与您的 MySQL 服务器版本相对应的手册,以在第 3 行的 ':id, :day_of, :day_of_advance, :day_prior, :default_time, :week_prior, :2_week_p' 附近使用正确的语法