Re: Inserting variables (Saga Continues)
| From: | Kamil Nowicki | Date: | Tue, 09 Oct 2001 17:13:36 +0000 |
| Subject: | Re: Inserting variables (Saga Continues) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-70519@lists.php.net to get a copy of this message | ||
> The key problem I have is that the number of "q1, q2" items is variable -
as
> few as just q1 other times q1, q2, ... q100 - which is why I "build" an
SQL
> statement from the form and then pass it to the script
How do You build it? Which part of SQL querry is from a form and which is
built? You say that AFTER it's been built it looks like:
<input type="hidden" name="sqlstatement" value="INSERT INTO tdefb4
VALUES
('$q1', '$q2', '2001-10-09')">
in HTML?
> I am still sooooo baffled why it is that I can not pass (as a HIDDEN
> variable from a form):
> $sqlstatement = "INSERT INTO mytable ('$q1', '$q2',
> '2001-10-09')"
>
> NOTE: when viewed in HTML format after being interpretted:
> <input type="hidden" name="sqlstatement" value="INSERT INTO tdefb4
> VALUES
> ('$q1', '$q2', '2001-10-09')">
>
> and then go:
> $query = $sqlstatement; //or "$sqlstatement"
> $result = MYSQL_QUERY($query);
Cause $q1 and $q2 in $querry aren't variables, but a string. SQL does not
understand '$q1' or any other variable and sees it as a text. You have to
fill the $querry with those varables values.
You can:
1. When You build Your $querry make it:
$querry = "INSERT INTO mytable VALUES ('$q1', '$q2', ... )";
(note the quoting way!!! )
or
$querry = "INSERT INTO mytable VALUES ('" . $q1 . "', '" . $q2
. "',
... )";
(result is the same)
and get the VALUES of $q1 and $q2 placed into the $querry
and pass that querry by a form (those $q1 $q2 variables are
now probably needless) and after recieving it from the form
pass it as a querry to database.
2. Build a querry without variables values eg. like this:
$querry = "INSERT INTO mytable VALUES ('shit_1', 'shit_2', ... )";
put it into a form (and those $q1, $q2 variables), recieve it from
the form and fill the variables into this prepared querry by
str_replace() or anything else.
3. Build PHP syntax which is able to build $querry:
$querry_builder = '<? $querry = "INSERT INTO mytable VALUES (\'$q1\',
\'$q2\', ... )"; ?>';
(note the quoting way!!! )
pass it to the form (and the variables):
<INPUT TYPE="hidden" NAME="querry_builder" VALUE="<?=
url_encode($querry_builder) ?>">
<INPUT TYPE="hidden" NAME="q1" VALUE="<?= $q1 ?>">
<INPUT TYPE="hidden" NAME="q2" VALUE="<?= $q2 ?>">
and when reciewed, interprete it:
eval( $querry_builder );
and get the proper querry int $querry variable to use:
$result = MYSQL_QUERY( $query );
That's all I can say for now.
Kamil 'Hilarion' Nowicki