动态的bindParam数量

问题描述 投票:-1回答:1

所以我试图在foreach中进行一定数量的bindParam调用,但由于某种原因它失败了。我知道$ sql变量工作正常,但我很确定它在bindParam失败了。这有什么理由吗?

$sql = "INSERT INTO " . $row1["rand"] . " (" . $areas . ") VALUES (" . $vals . ")";
echo $sql;
$entry2 = $conn->prepare("'".$sql."'");
//echo "swag";
foreach($splitHeader as $element){
    if(strlen($element)>0) {
        $thisVal = "':" . $element . "'";
        $entry2->bindParam($thisVal,$_POST[$element]);
    }
}
$entry2->execute();
php mysql pdo prepared-statement
1个回答
0
投票

您在查询中定义的参数数量必须与您绑定的参数数量相匹配。

您需要循环两次通过您的数据:一次动态构造一个sql语句(然后你可以prepare),然后第二次绑定参数,最后调用execute

以下是对代码的修改,演示了原理:

$cols = "";
$vals = "";
foreach( $splitHeader as $element ) {
    if( strlen($element) > 0 ) {
        if ( strlen($cols) > 0 ) {
            $cols .= ", ";
            $vals .= ", ";
        }
        $cols .= $element;
        $vals .= "?";
    }
}

$sql = "INSERT INTO " . $row1["rand"] . " (". $cols . ") VALUES(". $vals . ")";
echo $sql;
$sth = $conn->prepare($sql);

$i = 1;
foreach($splitHeader as $element){
    if( strlen($element) > 0 ) {
        $sth->bindParam( $i, $_POST[$element] );
        $i++;
    }
}

$sth->execute();
© www.soinside.com 2019 - 2024. All rights reserved.