[英]How to escape & and ' in mssql and Php?
我可以肯定在这种情况下我需要像preg_replace这样的东西,但是我不确定是否放它。 我有一个页面,允许人们搜索员工目录(PHP和MSSQL)。 他们可以按姓氏,建筑物或部门进行搜索。 姓氏和建筑物都可以,但是我在三个部门中遇到问题,两个部门中有一个&(例如Grants&Planning),当您单击该部门时,它不会返回任何结果,我认为是因为它无法将“&计划”识别为整个字符串的一部分。 我遇到的另一个问题是我有一个部门中有一个'部门,并且抛出错误
PHP警告:mssql_query()[function.mssql-query]:消息:第1行:'s'附近的语法不正确。 (严重性15)在179行上的C:\\ Inetpub \\ wwwroot \\ DACC \\ directory \\ dept.php中
* PHP警告:mssql_query()[function.mssql-query]:消息:字符串'ORDER BY Lastname'之前的引号引起来。 (严重性15)在179行的C:\\ Inetpub \\ wwwroot \\ DACC \\ directory \\ dept.php中*
第179行是这个... $query = mssql_query("SELECT * FROM directory WHERE Displayname = '$department' ORDER BY Lastname");
这是按部门查询页面的其余代码。...如果有人可以帮助我,我将不胜感激! `
$department = $_GET['dept'];
// This will evaluate to TRUE so the text will be printed.
if (isset($department)) {
$query = mssql_query("SELECT * FROM directory WHERE Displayname = '$department' ORDER BY Lastname");//$query = mssql_query("SELECT * FROM directory WHERE department IN (SELECT id FROM departments WHERE name='$department') ORDER BY Lastname");
$query2 = mssql_query(
"SELECT TOP 1 directory.FirstName, directory.Lastname, directory.email,
directory.phone, directory.office, directory.title, directory.displayname, departments.id AS dept_id, departments.name AS dept_name, departments.url AS dept_url
FROM directory
INNER JOIN departments on directory.displayname = departments.name
WHERE directory.displayname = '$department'
ORDER BY directory.LastName");
$numofrows = @mssql_num_rows($query);
// Check if there were any records
if (!mssql_num_rows($query)) {
echo 'No records found';
echo '<br /><a href="/directory/">Go Back</a>';
} else {
while($row1 = mssql_fetch_array($query2))
{
$dept_var = $row1['dept_name'];
$dept_id = $row1['dept_id'];
$dept_url = $row1['dept_url'];
print "<h3><a href=\"$dept_url\">$dept_var</a></h3>";
}
print "<table id=\"directory_table\" width=\"480\">
<tr>
<th>Name</th>
<th>Email</th>
<th>Phone</th>
<th>Office</th>
<th>Title</th>
</tr>";
for($i = 0; $i < $numofrows; $i++)
{
$row = mssql_fetch_array($query);
if($i % 2)
{
print '<tr bgcolor="#ffffff">';
}
else
{
print '<tr bgcolor="#eeeeee">';
}
print "<td>" . $row['Firstname'] . " " . $row['Lastname'] . " </td>";
print "<td><a href=\"mailto:" . $row['email'] . "\">" . $row['email']. "</a> </td>";
print "<td>" . $row['phone'] . " </td>";
print "<td>" . $row['Office'] . " </td>";
print "<td>" . $row['Title'] . " </td>";
print "</tr>";
}
print "</table>";
}
// Free the query result
mssql_free_result($query);
}
else
print "No Search Defined";
?>
编辑以显示更改可以尝试以下操作:
$serverName = "localhost"; //serverName\instanceName
$connectionInfo = array( "Database"=>"DACC", "UID"=>"daccweb", "PWD"=>"go");
$conn = sqlsrv_connect( $serverName, $connectionInfo);
if( $conn ) {
echo "Connection established.<br />";
}else{
echo "Connection could not be established.<br />";
die( print_r( sqlsrv_errors(), true));
}
//$conn = sqlsrv_connect("connection string here");
$queryParams = array($department);
//Selector links
print "<a href=\"/directory/\">Go back to main search</a><br />";
print "<u>Search for Employees:</u><br /><br />\n";
print "<br />";
//$officeloc = $_GET['building'];
$department = $_GET['dept'];
// This will evaluate to TRUE so the text will be printed.
if (isset($department)) {
$query = sqlsrv_query($conn, "SELECT * FROM directory WHERE Displayname = ? ORDER BY Lastname", $params);
$query2 = sqlsrv_query($conn, "SELECT TOP 1 directory.FirstName, directory.Lastname, directory.email,
directory.phone, directory.office, directory.title, directory.displayname,
departments.id AS dept_id, departments.name AS dept_name, departments.url AS dept_url
FROM directory
INNER JOIN departments on directory.displayname = departments.name
WHERE directory.displayname = ?
ORDER BY directory.LastName", $params);
新编辑
查询运行,但不回显/打印结果$ query = sqlsrv_query($ conn,“ SELECT * FROM directory WHERE Displayname =?ORDER BY Lastname”,$ params);
$query2 = sqlsrv_query($conn, "SELECT TOP 1 directory.FirstName, directory.Lastname, directory.email,
directory.phone, directory.office, directory.title, directory.displayname,
departments.id AS dept_id, departments.name AS dept_name, departments.url AS dept_url
FROM directory
INNER JOIN departments on directory.displayname = departments.name
WHERE directory.displayname = ?
ORDER BY directory.LastName", $params);
$numofrows = @@sqlsrv_has_rows($query);
// Check if there were any records
if (!@sqlsrv_has_rows($query)) {
echo 'No records found';
echo '<br /><a href="/directory/">Go Back</a>';
} else {
while($row1 = sqlsrv_fetch_array($query2))
{
$dept_var = $row1['dept_name'];
$dept_id = $row1['dept_id'];
$dept_url = $row1['dept_url'];
print "<h3><a href=\"$dept_url\">$dept_var</a></h3>";
//echo "</h3><br />";
}
print "<table id=\"directory_table\" width=\"480\">
<tr>
<th>Name</th>
<th>Email</th>
<th>Phone</th>
<th>Office</th>
<th>Title</th>
</tr>";
for($i = 0; $i < $numofrows; $i++)
{
$row = sqlsrv_fetch_array($query);
if($i % 2)
{
print '<tr bgcolor="#ffffff">';
}
else
{
print '<tr bgcolor="#eeeeee">';
}
print "<td>" . $row['Firstname'] . " " . $row['Lastname'] . " </td>";
print "<td><a href=\"mailto:" . $row['email'] . "\">" . $row['email']. "</a> </td>";
print "<td>" . $row['phone'] . " </td>";
print "<td>" . $row['Office'] . " </td>";
print "<td>" . $row['Title'] . " </td>";
print "</tr>";
}
print "</table>";
}
// Free the query result
sqlsrv_free_stmt($query);
}
else
print "No Search Defined";
您可以在PHP和MSSQL中使用SQL参数,看一下:
http://blogs.msdn.com/b/sqlphp/archive/2008/09/30/how-and-why-to-use-parameterized-queries.aspx
您的参数值将自动转义,无需您进行任何操作。
您需要使用sqlsrv驱动程序,请参见: http ://www.php.net/manual/zh/sqlsrv.setup.php
为了获得行数,我们还需要指定一些查询选项。 (请查看http://www.php.net/manual/zh-CN/function.sqlsrv-num-rows.php和http://msdn.microsoft.com/zh-CN/library/hh487160.aspx )
$conn = sqlsrv_connect("connection string here");
$queryParams = array($department);
$queryOptions = array( "Scrollable" => "buffered" );
$query = sqlsrv_query($conn, "SELECT * FROM directory WHERE Displayname = ? ORDER BY Lastname", $queryParams, $queryOptions);
$query2 = sqlsrv_query($conn, "SELECT TOP 1 directory.FirstName, directory.Lastname, directory.email,
directory.phone, directory.office, directory.title, directory.displayname,
departments.id AS dept_id, departments.name AS dept_name, departments.url AS dept_url
FROM directory
INNER JOIN departments on directory.displayname = departments.name
WHERE directory.displayname = ?
ORDER BY directory.LastName", $queryParams, $queryOptions);
$numofrows = sqlsrv_num_rows($query);
请注意,构建数组的顺序必须与?的顺序匹配?
符号出现在查询中。 由于您在每个查询中仅使用一个参数,并且它们相同,因此您只需要构建一个数组。
然后,您可以将所有mssql函数替换为sqlsrv函数,以获取函数及其用法的列表,请参阅文档: http ://www.php.net/manual/zh/ref.sqlsrv.php
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.