我已经得到了以下代码,它看起来相当健壮:它适用于不同的语言(UTF-8),现在我想将结果存储在数据库中。我的问题是我只熟悉旧的,过时的mysql语句,并想使用mysqli。任何人都可以指向一个简单但安全的函数,它将输入A并将其存储在数据库中...然后告诉我在这个代码中我需要添加它的位置?
<?php
/*
* PHP 5.3.18 on windows XP
*
* I don't have open_ssl active from PHP so used MCRYPT_RAND for the salt.
* It is adequate for this exercise.
*
* As the encoded SALT and encrypted output are binary code i have converted all
* the output to Base64 encoding to ensure it is HTML safe.
*
* It selects the appropriate default action in the 'do' select list.
*
* There is a new 'salt' generated at each encryption and the user is prevented from
* changing it by making the display field as 'readonly'. Normally this would be a 'hidden' field'.
*
*/
$isEncrypted = null; // used to set default output options
// i like to pre-declare the script 'global' variables
$key_size = mcrypt_get_key_size(MCRYPT_RIJNDAEL_128, MCRYPT_MODE_CFB);
$iv_size = mcrypt_get_iv_size(MCRYPT_RIJNDAEL_128, MCRYPT_MODE_CFB);
if($_POST){ // we have some input...
$encryption_key = $_POST["key"];
$string = $_POST["msg"]; // this may be base64 encoded...
if($_POST["do"]=="encrypt"){
$isEncrypted = true; // used to set defaults
$iv = mcrypt_create_iv($iv_size, MCRYPT_RAND); // new salt with each encryption
$result = mcrypt_encrypt(MCRYPT_RIJNDAEL_128, $encryption_key, $string, MCRYPT_MODE_CFB, $iv);
$result = base64_encode($result); // $result is binary so encode as HTML safe.
}else{
$isEncrypted = false; // used to set defaults
$iv = base64_decode($_POST["iv"]); // get current salt converted back to binary format
$string = base64_decode($string); // convert encoded text back to binary string
$result = mcrypt_decrypt(MCRYPT_RIJNDAEL_128, $encryption_key, $string, MCRYPT_MODE_CFB, $iv);
}
}else{ // no input so create something useful...
$isEncrypted = false; // used to set default actions
$result = 'enter text to encrypt...'; // sample text
$iv = mcrypt_create_iv($iv_size, MCRYPT_RAND); // new salt
$encryption_key = substr('testing!' . uniqid() . '!testing', 0, $key_size);
}
?>
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Test Encryption with base64 encoding.</title>
</head>
<body>
<div class="main" id="main">
<!-- heading -->
<strong><?php echo $isEncrypted ? 'Encrypted' : 'Decrypted'; ?></strong><br/>
<form method="POST" action="">
<!-- do not allow the user to change the salt by setting 'readonly' -->
<input type="text" value="<?php echo base64_encode($iv); ?>" readonly name="iv"/> <br/>
<!-- supply a suggested password but the user can change it -->
<input type="text" value="<?php echo $encryption_key; ?>" name="key"/><br/>
<!-- either show the encoded text as HTML safe string -->
<!--- or show as plain text -->
<textarea name="msg" ><?php echo $result; ?></textarea><br/>
<!-- set the appropriate action as the default -->
<select name="do">
<option <?php echo $isEncrypted ? 'selected' : ''; ?>>decrypt</option>
<option <?php echo $isEncrypted ? '' : 'selected'; ?>>encrypt</option>
</select><br/>
<input type="submit" value="GO"/>
</form>
</div>
</body>
</html>
答案 0 :(得分:1)
你仍然会写'老'&#39; MySQL语句,因为&#39; mysqli&#39;是一个改进的驱动程序(因此,&#34; i&#34;),以利用MySQL&gt; = 4.1中的功能。它被认为是双程序和面向对象的API&#39;。例如,要连接到MySQL DB,您可以执行either of the following:
// mysqli, procedural way
$mysqli = mysqli_connect('localhost','username','password','database');
// mysqli, object oriented way
$mysqli = new mysqli('localhost','username','password','database');
您还应该查看PDO driver(PHP数据对象),它提供了一个数据访问抽象层,允许您的代码访问除MySQL以外的更多DBM。