php防sql注入資料model類

來源:互聯網
上載者:User
class Model{
protected $tableName="";//表名稱
protected $pOb;//pdo類對象
function __construct(){
$pdo=new PDO("mysql:host=".DB_HOST.";dbname=".DB_NAME,DB_USERNAME,DB_PASSWORD);
$pdo->exec("set names ".DB_CHARSET);
$this->pOb=$pdo;
}
/*
* 作用:增
* 參數:array $arr exp:array('欄位名'=>值,'欄位名'=>值,....)
* return:int|false
*/
function add($arr){
//拼sql語句
$kArr=array_keys($arr);
$kStr=join(",",$kArr);
$vArr=array_values($arr);

$pStr = '';
foreach ($vArr as $s=>$y){
$vname = "p".$s;
$pStr.=':'.$vname.',';
}
$pStr = substr($pStr,0,-1);

$sql = "insert into {$this->tableName}($kStr) values($pStr)";

print_r($sql);
$pdoS = $this->pOb ->prepare($sql);
foreach ($vArr as $k=>$y){
$vname = "p".$k;
$$vname = $y;
var_dump($vname,$$vname);
$pdoS -> bindParam(":".$vname, $$vname,PDO::PARAM_STR);

}
$re = $pdoS -> execute();
if($re){//添加成功
//返回主鍵id值
return $this->pOb->lastInsertId();
}
//傳回值
return $re;
}
public function delete($arrWhere){
if(!empty($arrWhere)){
$strW = " where ";
foreach($arrWhere as $kW=>$vW){
$kn = str_replace(":", "", $kW);
if(count($arrWhere)==1){
$strW .= $kn."=".$kW;
}else{
$strW .= $kn."=".$kW." and ";
}
}
if(count($arrWhere)>1){
$strW .= " 1=1 ";
}
}
$sql = "delete from {$this->tableName}".$strW;
print_r($sql);
$pdoS = $this->pOb->prepare($sql);
foreach ($arrWhere as $kW=>$vW){
$kn = str_replace(":", "", $kW);
$$kn = $vW;
if(is_int($vW)){
$pdoS->bindParam($kW,$$kn,PDO::PARAM_INT);
}else if(is_float($vW)){
$pdoS->bindParam($kW,$$kn,PDO::PARAM_INT);
}else{
$pdoS->bindParam($kW,$$kn,PDO::PARAM_STR);
}
}
$re=$pdoS->execute();
if($re){
return true;
}else {
return false;
}

}
function update($arrSet,$arrWhere){
//拼sql語句
$str = "";
$n=0;
foreach ($arrSet as $kS=>$vS){

$str .= ",".$kS."=:p".$n++;
}
$str = substr($str, 1);
foreach($arrWhere as $kW=>$vW){
$kn=str_replace(":","",$kW);
if(count($arrWhere)==1){
$strW .= $kn."=".$kW;
}else{
$strW .= $kn."=".$kW." and ";
}
}
if(count($arrWhere)>1){
$strW .= " 1=1 ";
}

$sql="update {$this->tableName} set {$str} where ".$strW;
//print_r($sql);

$pdoS=$this->pOb->prepare($sql);
$x = 0;
foreach($arrSet as $kS=>$vS){

$kS = ":p".$x++;
$$kS = $vS;

if(is_int($vS)){
$pdoS->bindParam($kS,$$kS,PDO::PARAM_INT);
}else if(is_float($vS)){
$pdoS->bindParam($kS,$$kS,PDO::PARAM_INT);
}else{
$pdoS->bindParam($kS,$$kS,PDO::PARAM_STR);
}
}


foreach($arrWhere as $kW=>$vW){
$kn=str_replace(":","",$kW);
$$kn=$vW;//$p0 $p1 $p2
if(is_int($vW)){
$pdoS->bindParam($kW,$$kn,PDO::PARAM_INT);
}else if(is_float($vW)){
$pdoS->bindParam($kW,$$kn,PDO::PARAM_INT);
}else{
$pdoS->bindParam($kW,$$kn,PDO::PARAM_STR);
}
}
$re=$pdoS->execute();
if($re){
return true;

}else{
return false;
}

}
//查
function select($field="*",$ArrayWhere="",$order="",$limit=""){
if(!empty($ArrayWhere)){
$strW = " where ";
foreach($ArrayWhere as $kW=>$vW){
$kn=str_replace(":","",$kW);
if(count($ArrayWhere)==1){
$strW .= $kn."=".$kW;

}else{
$strW .= $kn."=".$kW." and ";
}
}
if(count($ArrayWhere)>1){
$strW .= " 1=1 ";
}
}
if(!empty($order)){
$order="order by ".$order;
}
if(!empty($limit)){
$limit="limit ".$limit;
}
//select 欄位列表 from 表名 where 條件 order by 欄位 desc|asc limit start,length;
$sql="select {$field} from {$this->tableName} {$strW} {$order} {$limit}";
//print_r($sql);
$pdoS=$this->pOb->prepare($sql);
if(!empty($ArrayWhere)){
foreach($ArrayWhere as $kW=>$vW){
$kn=str_replace(":","",$kW);
$$kn=$vW;
if(is_int($vW)){
$pdoS->bindParam($kW,$$kn,PDO::PARAM_INT);
}else if(is_float($vW)){
$pdoS->bindParam($kW,$$kn,PDO::PARAM_INT);
}else{
$pdoS->bindParam($kW,$$kn,PDO::PARAM_STR);
}
}
}
$re=$pdoS->execute();
if($re){
$pdoS->setFetchMode(PDO::FETCH_ASSOC);
return $pdoS->fetchAll();
}else {
return false;
}

}


}
  • 聯繫我們

    該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

    如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

    A Free Trial That Lets You Build Big!

    Start building with 50+ products and up to 12 months usage for Elastic Compute Service

    • Sales Support

      1 on 1 presale consultation

    • After-Sales Support

      24/7 Technical Support 6 Free Tickets per Quarter Faster Response

    • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.