PHP / MySQL多个查询好吗?

时间:2018-05-02 11:39:36

标签: php mysql

我的问题是关于性能和脚本优化。我是PHP的新手,我有以下内容:

$Connection = new mysqli($Server, $DBUsername, $DBPassword, $DBName);
$Connection->query("UPDATE Basket SET Apples='$Apples', Oranges='$Oranges', Bananas='$Bananas' WHERE BasketName='$BasketName'"); 
$Connection->query("UPDATE Bag SET Napkins='$Napkins' WHERE BagName='$BagName'");
$Connection->query("UPDATE Drinks SET Water='$Water' WHERE DrinksName='$DrinksName'");

我有多个$ Connection->查询,每个表一个或者有更好的方法可以更快地写这个吗?

1 个答案:

答案 0 :(得分:2)

首先,您的代码容易受到SQL injection的攻击。你应该尽快切换到预备语句。

使用mysqli_real_escape_string不足以阻止SQL注入。见Is “mysqli_real_escape_string” enough to avoid SQL injection or other SQL attacks?

准备好的陈述的example

<?php
$servername = "localhost";
$username = "username";
$password = "password";
$dbname = "myDB";

// Create connection
$conn = new mysqli($servername, $username, $password, $dbname);

// Check connection
if ($conn->connect_error) {
    die("Connection failed: " . $conn->connect_error);
}

// prepare and bind
$stmt = $conn->prepare("INSERT INTO MyGuests (firstname, lastname, email) VALUES (?, ?, ?)");
$stmt->bind_param("sss", $firstname, $lastname, $email);

// set parameters and execute
$firstname = "John";
$lastname = "Doe";
$email = "john@example.com";
$stmt->execute();

回答您原来的问题。您可以使用mysqli::multi_query。如果查询按查询拆分查询,我个人觉得它更清晰。