2013-03-07 107 views
0

在Zend Framework 2中进行数据库查询时,我应该如何清理用户提交的值?例如,$下面的SQL IDZF2为DB查询清理变量

$this->tableGateway->adapter->query(
    "UPDATE comments SET spam_votes = spam_votes + 1 WHERE comment_id = '$id'", 
    \Zend\Db\Adapter\Adapter::QUERY_MODE_EXECUTE 
); 

回答

4

可以传递,当你执行参数..

$statement = $this->getAdapter()->query("Select * from test WHERE id = ?"); 
$result = $statement->execute(array(99)); 

$resultSet = new ResultSet; 
$resultSet->initialize($result); 

您也可以将其直接转给查询方法

$statement = $this->getAdapter()->query(
    "Select * from test WHERE id = ?", 
    array(99) 
); 
$result = $statement->execute(); 

$resultSet = new ResultSet; 
$resultSet->initialize($result); 

两个将产生查询“Select * from test WHERE id ='99'”

如果您想使用命名参数:

$statement = $this->getAdapter()->query("Select * from test WHERE id = :id"); 
$result = $statement->execute(array(
    ':id' => 99 
)); 

$resultSet = new ResultSet; 
$resultSet->initialize($result); 

如果你想你的报价表/字段名等:

$tablename = $adapter->platform->quoteIdentifier('tablename'); 

$statement = $this->getAdapter()->query("Select * from {$tablename} WHERE id = :id"); 
$result = $statement->execute(array(
    ':id' => 99 
)); 
+0

真棒,谢谢!我希望这不是愚蠢的,但该数组也可以参数化? ''select * from test WHERE id =:id“','array(':id'=> 99)'? – Wige 2013-03-07 15:09:31

+0

我相信如此:) – Andrew 2013-03-07 15:11:08

+0

更新了你的例子 – Andrew 2013-03-07 16:09:13