在准备语句中转换PHP准备语句

时间:2015-08-04 21:27:03

标签: php mysqli

我正在尝试将以下php代码转换为准备好的语句。

下面的代码会查询尚未开始的所有游戏,删除所有选择,然后插入新的选择。

$sql = "SELECT gameID, weekNum, gameTimeEastern FROM htb_schedule
            WHERE weekNum = " . $week . "
            AND (DATE_ADD(NOW(), INTERVAL " . SERVER_TIMEZONE_OFFSET . " HOUR) < gameTimeEastern
            AND DATE_ADD(NOW(), INTERVAL " . SERVER_TIMEZONE_OFFSET . " HOUR) < '" . $cutoffDateTime . "') ";

$query = $mysqli->query($sql);

if ($query->num_rows > 0) {

    while ($row = $query->fetch_assoc()) {

        $sql = "DELETE FROM htb_picks WHERE userID = " . $user->userID . " AND gameID = " . $row['gameID'];
        $mysqli->query($sql);

        if (!empty($_POST['game' . $row['gameID']])) {

            $sql = "INSERT INTO htb_picks (userID, gameID, pickID, weekN, timestamp) VALUES (" . $user->userID . ", " . $row['gameID'] . ", '" . $_POST['game' . $row['gameID']] . "', " . $week . ", NOW() )";
            $mysqli->query($sql);

        }
    }
}

以下代码是我对准备好的陈述的尝试。

$sql = "SELECT gameID, weekNum, gameTimeEastern FROM htb_schedule
            WHERE weekNum = ?
            AND (DATE_ADD(NOW(), INTERVAL " . SERVER_TIMEZONE_OFFSET . " HOUR) < gameTimeEastern
            AND DATE_ADD(NOW(), INTERVAL " . SERVER_TIMEZONE_OFFSET . " HOUR) < '" . $cutoffDateTime . "') ";

$stmt = $mysqli->prepare($sql);
$stmt->bind_param("i", $week);
$stmt->execute();
$stmt->bind_result($gameID, $weekNum, $gameTimeEastern);

if ($stmt->num_rows > 0) {

    while ($stmt->fetch()) {

        $sql = "DELETE FROM htb_picks WHERE userID = ? AND gameID = ? ";
        $stmt = $mysqli->prepare($sql);
        $stmt->bind_param("ii", $user->userID, $gameID);
        $stmt->execute();
        $stmt->close();

        if (!empty($_POST['game' . $row['gameID']])) {

            $sql = " INSERT INTO htb_picks (userID, gameID, pickID, weekN, timestamp) VALUES (?, ?, ?, ?, NOW()) ";
            $stmt = $mysqli->prepare($sql);
            $stmt->bind_param("iisi", $user->userID, $gameID, $_POST['game' . $row['gameID']], $week);
            $stmt->execute();
            $stmt->close();

        }
    }
}
$stmt->free_result();

代码假设是DELETE和INSERT结果,但它没有这样做。我做错了什么?

如果我使用下面的代码,它将起作用,但第一个sql不是准备好的声明。

$sql = "SELECT * FROM htb_schedule
            WHERE weekNum = " . $week . "
            AND (DATE_ADD(NOW(), INTERVAL " . SERVER_TIMEZONE_OFFSET . " HOUR) < gameTimeEastern
            AND DATE_ADD(NOW(), INTERVAL " . SERVER_TIMEZONE_OFFSET . " HOUR) < '" . $cutoffDateTime . "') ";

$query = $mysqli->query($sql);

if ($query->num_rows > 0) {

    while ($row = $query->fetch_assoc()) {

        $sql = "DELETE FROM htb_picks WHERE userID = ? AND gameID = ? ";

        $stmt = $mysqli->prepare($sql);

        $stmt->bind_param("ii", $user->userID, $row['gameID']);

        $stmt->execute();

        $stmt->close();

        if (!empty($_POST['game' . $row['gameID']])) {

            $sql = " INSERT INTO htb_picks (userID, gameID, pickID, weekN, timestamp) VALUES (?, ?, ?, ?, NOW()) ";

            $stmt = $mysqli->prepare($sql);

            $stmt->bind_param("iisi", $user->userID, $row['gameID'], $_POST['game' . $row['gameID']], $week);

            $stmt->execute();

            $stmt->close();

        }
    }
}
$query->free;

1 个答案:

答案 0 :(得分:0)

当您在while循环中时,您正在编写控制while循环的$stmt。你甚至可以->close()

当您进入循环

时,您需要做的就是为语句使用不同的变量名称

此外,您应该检查每个mysqli命令的状态。

$sql = "SELECT gameID, weekNum, gameTimeEastern FROM htb_schedule
            WHERE weekNum = ?
            AND (DATE_ADD(NOW(), INTERVAL " . SERVER_TIMEZONE_OFFSET . " HOUR) < gameTimeEastern
            AND DATE_ADD(NOW(), INTERVAL " . SERVER_TIMEZONE_OFFSET . " HOUR) < '" . $cutoffDateTime . "') ";

$stmt = $mysqli->prepare($sql);
if ( ! $stmt ) {
    echo $mysqli->error;
}
$stmt->bind_param("i", $week);

if ( ! $stmt->execute() ) {
    echo $stmt->error;
}

$stmt->bind_result($gameID, $weekNum, $gameTimeEastern);

if ($stmt->num_rows > 0) {

    while ($stmt->fetch()) {

        $sql = "DELETE FROM htb_picks WHERE userID = ? AND gameID = ? ";
        $stmt2 = $mysqli->prepare($sql);
        if ( ! $stmt2 ) {
            echo $mysqli->error;
        }
        $stmt2->bind_param("ii", $user->userID, $gameID);
        if ( ! $stmt2->execute() )
        {
            echo $stmt2->error;
            exit;
         }

        $stmt2->close();

        // stmt2 is closed and finished with, so its name can be reused

        if (!empty($_POST['game' . $row['gameID']])) {

            $sql = "INSERT INTO htb_picks 
                            (userID, gameID, pickID, weekN, timestamp) 
                     VALUES (?, ?, ?, ?, NOW()) ";
            $stmt2 = $mysqli->prepare($sql);
            if ( ! $stmt2 ) {
                echo $mysqli->error;
            }

            $stmt2->bind_param("iisi", $user->userID, 
                                       $gameID, 
                                       $_POST['game' . $row['gameID']], 
                                       $week);

            if ( ! $stmt2->execute() )
            {
                echo $stmt2->error;
                exit;
             }

            $stmt2->close();

        }
    }
}
$stmt->close();