根据用户输入编写包含变量WHERE的查询

时间:2014-11-24 03:45:39

标签: php mysql pdo

我遇到查询问题。我希望它做的是检查每个变量是否存在,如果它们不存在则忽略它们。我还想在表格中显示结果。任何帮助将不胜感激!

到目前为止我所拥有的:这是我的代码。此时,它返回一个包含数据库所有结果的数组,但是如果我将WHERE子句中的OR更改为AND,则需要填充所有字段。我希望用户能够输入他们知道的尽可能多的信息,以便显示所有可能的结果。

<?php require("common.php");?>
<?php
if(!empty($_POST))
{
$sth = $db->prepare("SELECT * FROM customer WHERE First_name LIKE '%$First_name%' OR Surname LIKE '%$Surname%' OR DOB LIKE '$DOB' OR Street LIKE '%$Street%' OR Suburb LIKE '$Suburb' OR State LIKE '$State' OR Postcode LIKE '$Postcode' OR Phone LIKE '$Phone'");
$sth->execute();

/* Fetch all of the remaining rows in the result set */
print("Fetch all of the remaining rows in the result set:\n");
$result = $sth->fetchAll();
print_r($result);



$First_name = $_POST['First_name'];
$Surname = $_POST['Surname'];
$DOB = $_POST['DOB'];
$Street = $_POST['Street'];
$Suburb = $_POST['Suburb'];
$State = $_POST['State'];
$Postcode = $_POST['Postcode'];
$Phone = $_POST['Phone'];
}
?>
<fieldset><legend>Find a customer</legend>
<form name="querycustomerform" method="post" action="qcustomer.php">
    <table class="five">
        <tr>
            <td colspan="4">
                <h3>Please fill out as many details as possible</h3>
            </td>
        </tr>
        <tr>
            <td>
                <input type="text" name="First_name" maxlength="30" size="30" placeholder="First name">
            </td>
            <td>
                <input type="text" name="Surname" maxlength="30" size="30" placeholder="Surname">
            </td>
            <td style="text-align: right">Date of Birth:</td>
            <td>
                <input type="date" name="DOB">
            </td>
        </tr>
        <tr>
            <td>
                <input type="text" name="Street" maxlength="40" size="30" placeholder="Street Address">
            </td>
            <td>
                <input type="text" name="Suburb" maxlength="15" size="30" placeholder="Suburb">
            </td>
            <td>
                <select name="State">
                <option value="">State</option>
                <option value="ACT">Australian Capital Territory</option>
                <option value="NSW">New South Wales</option>
                <option value="NT">Northern Territory</option>
                <option value="QLD">Queensland</option>
                <option value="SA">South Australia</option>
                <option value="TAS">Tasmania</option>
                <option value="VIC">Victoria</option>
                <option value="WA">Western Australia</option>
                </select>
            </td>
            <td>
                <input type="text" name="Postcode" maxlength="4" size="30" placeholder="Postcode">
            </td>
        </tr>
        <tr>
            <td>
                <input type="text" name="Phone" maxlength="15" size="30" placeholder="Phone Number">
            </td>
            <td>
            </td>
            <td>
            </td>
            <td>
                <input class="button" type="submit" value="Search">
            </td>
        </tr>
    </table> 
</form>
</fieldset>

2 个答案:

答案 0 :(得分:1)

OR 条件要求必须满足任何条件(即:condition1,condition2,condition_n)才能将记录包含在结果集中。而 AND 条件要求必须满足所有条件(即:condition1,condition2,condition_n)。根据您的要求, OR 条件是必需的。

您需要构建动态查询才能执行此操作。从基本存根开始

$sql = "SELECT * FROM customer";

然后你需要将initial子句设置为WHERE。

$clause = " WHERE ";//Initial clause

您需要一个数组来存储参数

$paramArray =array();

开始构建查询。注意我已经从POST更改为GET,因为它更容易测试 另请参阅PDO WIKI以了解占位符中的%。占位符不能表示查询的任意部分,而只能表示完整的数据文字。

if(isset($_GET['First_name'])){
    $First_name = $_GET['First_name'];
    $sql .= "$clause First_name LIKE ?";
    $clause = " OR ";//Change clause
    array_push($paramArray,"%$First_name%");
}   

继续下一句

if(isset($_GET['Surname'])){
    $Surname = $_GET['Surname'];
    $sql .= "$clause Surname LIKE ?";
    $clause = " OR ";
    array_push($paramArray,"%$Surname%");
}   

如上所述添加其余条款

测试结果,测试后删除&amp;将GET更改为POST

echo $sql ;
echo "<br>";
print_r($paramArray);

准备并执行查询

$sth = $db->prepare($sql);
$sth->execute($paramArray);

来自test.php?First_name=dave&Surname=smith

的典型测试结果
SELECT * FROM customer WHERE First_name LIKE ? OR Surname LIKE ?
Array ( [0] => %dave% [1] => %smith% )

来自test.php?Surname=smith

SELECT * FROM customer WHERE Surname LIKE ?
Array ( [0] => %smith% )

答案 1 :(得分:-1)

尝试更改

$sth = $db->prepare("SELECT * FROM customer WHERE First_name LIKE '%$First_name%' OR Surname LIKE '%$Surname%' OR DOB LIKE '$DOB' OR Street LIKE '%$Street%' OR Suburb LIKE '$Suburb' OR State LIKE '$State' OR Postcode LIKE '$Postcode' OR Phone LIKE '$Phone'");

$sth = $db->prepare("SELECT * FROM customer WHERE First_name LIKE '%'".$First_name."'%' OR ...

从文字字符串中取出$ First_name,并将其与文字字符串连接起来。你正在做的是字面上搜索&#34; $ First_name&#34;,而不是$ First_Name变量的值。从外观的角度来看,它有点混乱,但我发现将文本与变量连接起来更安全,而不是在引号内扩展变量。

的Darryl