Re: Use the User Input Critia as part of Query! (Mysql)
| From: | Hugh Bothwell | Date: | Mon, 03 Sep 2001 17:37:16 +0000 |
| Subject: | Re: Use the User Input Critia as part of Query! (Mysql) | ||
| References: | 1 2 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-12123@lists.php.net to get a copy of this message | ||
"Jason Wong" <phplist@gremlins.com.hk> wrote in message
news:021701c13489$245b1f40$0400000a@gremlins.com.hk...
> ----- Original Message -----
> From: Jack <jack@nedcor.com>
> To: <php-db@lists.php.net>; <php-windows@lists.php.net>
> Sent: Monday, September 03, 2001 10:35 PM
> Subject: [PHP-DB] Use the User Input Critia as part of Query! (Mysql)
>
> > $query="select name,department,Leave_From,Leave_To,
> > Leave_Total,Reason from leaverequest where
> > Staff_Number="<?print("$StaffNum");?>" and authorized
> > is null";
> >
> Try something like:
> $query="select name,department,Leave_From,Leave_To,
> Leave_Total,Reason from leaverequest where Staff_Number
> ='$StaffNum' and authorized is null";
Also, for security, you would be wise to cast $StaffNum
to int before using it:
$StaffNum = (int) $StaffNum;
$query =
"SELECT "
."name,department,Leave_From,Leave_To,"
."Leave_Total,Reason "
."FROM leaverequest "
."WHERE Staff_Number=$StaffNum "
."AND authorized IS NULL";
HTH