我有来自查询字符串的变量(不用担心我安全地做到了)。请告诉我如何将变量添加到我的 sql 查询中。我的变量:
$order = "ASC";
if(isset($_POST['sort'])){
if($_POST['sort']=="date"){
$sort = "date";
}
else if($_POST['sort']=="pricelow"){
$sort = "Price";
}
else if($_POST['sort']=="pricehigh"){
$sort = "Price";
$order = "DESC";
}
}
我的查询如下:
mysql_query("SELECT * FROM event ORDER BY '$sort' '$order'");