Inserting variables (Saga Continues)

From: Date: Tue, 09 Oct 2001 16:39:11 +0000
Subject: Inserting variables (Saga Continues)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-70511@lists.php.net to get a copy of this message
The key problem I have is that the number of "q1, q2" items is variable - as few as just q1 other times q1, q2, ... q100 - which is why I "build" an SQL statement from the form and then pass it to the script I am still sooooo baffled why it is that I can not pass (as a HIDDEN variable from a form): $sqlstatement = "INSERT INTO mytable ('$q1', '$q2', '2001-10-09')" NOTE: when viewed in HTML format after being interpretted: <input type="hidden" name="sqlstatement" value="INSERT INTO tdefb4 VALUES ('$q1', '$q2', '2001-10-09')"> and then go: $query = $sqlstatement; //or "$sqlstatement" $result = MYSQL_QUERY($query); "Kamil Nowicki" <hilarion@elfin.pl> wrote in message news:00c401c150d0$ff24b560$d101a8c0@elfin... > > >From a form, I pass the variables "$q1" and $q2" > > I also pass the following ATTEMPTS on an variable that is an SQL > statement: > > > > INSERT INTO mytable ('$q1', '$q2', '2001-10-09') > > or > > INSERT INTO mytable ("$q1", "$q2", "2001-10-09") > > > > I have tried executing the SQL statement like this: > > > > $query = $sqlstatement; > > $result = MYSQL_QUERY($query); > > > > as well as > > > > $query = "$sqlstatement"; > > $result = MYSQL_QUERY($query); > > > > > > No matter what I get the values literally "q1" and "q2" sent to the table > > and NOT their respective values > Cause when You pass something from a form thai it is a string (no matter if > there's > $q1 entered into it and that You have $q1 declared) and it's not > interpreted, so > the querry contains '$q1', '$q2' strings, not the variables values. > > The solution for You was allready presented: > > do not pass the querry as You did, but like this: > > <INPUT TYPE="whatever" NAME="querry" VALUE="INSERT INTO mytable > ('replacer_1', 'replacer_2', '2001-10-09')"> > <INPUT TYPE="whatever" NAME="q1" VALUE="some_value_1"> > <INPUT TYPE="whatever" NAME="q2" VALUE="some_value_2"> > > and handle it: > > $querry = ereg_replace( "replacer_1", $q1, $querry ); > $querry = ereg_replace( "replacer_2", $q2, $querry ); > $result = MYSQL_QUERY($query); > > Kamil 'Hilarion' Nowicki >

« previous php.general (#70511) next »