2010-03-28 22:10:10 +00:00
<?xml version="1.0" encoding="utf-8"?>
2009-07-11 08:37:21 +00:00
<!-- $Revision$ -->
2005-03-20 08:54:31 +00:00
<!-- splitted from ./en/functions/pgsql.xml, last change in rev 1.2 -->
2007-06-20 22:25:43 +00:00
<refentry xml:id= "function.pg-query-params" xmlns= "http://docbook.org/ns/docbook" >
2005-03-20 08:54:31 +00:00
<refnamediv >
<refname > pg_query_params</refname>
2005-04-03 07:21:50 +00:00
<refpurpose > Submits a command to the server and waits for the result, with the ability to pass parameters separately from the SQL command text.</refpurpose>
2005-03-20 08:54:31 +00:00
</refnamediv>
<refsect1 role= "description" >
&reftitle.description;
<methodsynopsis >
<type > resource</type> <methodname > pg_query_params</methodname>
2009-01-19 15:13:01 +00:00
<methodparam choice= "opt" > <type > resource</type> <parameter > connection</parameter> </methodparam>
2005-03-20 08:54:31 +00:00
<methodparam > <type > string</type> <parameter > query</parameter> </methodparam>
<methodparam > <type > array</type> <parameter > params</parameter> </methodparam>
</methodsynopsis>
<para >
2005-04-03 07:21:50 +00:00
Submits a command to the server and waits for the result, with the ability
to pass parameters separately from the SQL command text.
2005-03-20 08:54:31 +00:00
</para>
<para >
2005-04-03 07:21:50 +00:00
<function > pg_query_params</function> is like <function > pg_query</function> ,
2005-04-03 07:27:30 +00:00
but offers additional functionality: parameter
2005-04-03 07:21:50 +00:00
values can be specified separately from the command string proper.
<function > pg_query_params</function> is supported only against PostgreSQL 7.4 or
2005-04-03 07:27:30 +00:00
higher connections; it will fail when using earlier versions.
2005-03-20 08:54:31 +00:00
</para>
2005-04-03 07:21:50 +00:00
<para >
2013-05-16 19:58:22 +00:00
If parameters are used, they are referred to in the
<parameter > query</parameter> string as $1, $2, etc. The same parameter may
appear more than once in the <parameter > query</parameter> ; the same value
will be used in that case. <parameter > params</parameter> specifies the
actual values of the parameters. A &null; value in this array means the
corresponding parameter is SQL <literal > NULL</literal> .
2005-04-03 07:21:50 +00:00
</para>
<para >
The primary advantage of <function > pg_query_params</function> over <function > pg_query</function>
2005-04-03 07:27:30 +00:00
is that parameter values
may be separated from the <parameter > query</parameter> string, thus avoiding the need for tedious
2005-04-03 07:21:50 +00:00
and error-prone quoting and escaping. Unlike <function > pg_query</function> ,
2005-04-03 07:27:30 +00:00
<function > pg_query_params</function> allows at
most one SQL command in the given string. (There can be semicolons in it,
2005-04-03 07:21:50 +00:00
but not more than one nonempty command.)
2005-03-20 08:54:31 +00:00
</para>
</refsect1>
2005-04-03 07:27:30 +00:00
<refsect1 role= "parameters" >
&reftitle.parameters;
<para >
<variablelist >
<varlistentry >
<term > <parameter > connection</parameter> </term>
<listitem >
<para >
PostgreSQL database connection resource. When
<parameter > connection</parameter> is not present, the default connection
is used. The default connection is the last connection made by
<function > pg_connect</function> or <function > pg_pconnect</function> .
</para>
</listitem>
</varlistentry>
<varlistentry >
<term > <parameter > query</parameter> </term>
2005-04-03 07:21:50 +00:00
<listitem >
2005-04-03 07:27:30 +00:00
<para >
2008-12-16 04:22:48 +00:00
The parameterized SQL statement. Must contain only a single statement.
2005-04-03 07:27:30 +00:00
(multiple statements separated by semi-colons are not allowed.) If any parameters
are used, they are referred to as $1, $2, etc.
</para>
2013-08-30 11:50:52 +00:00
<para >
User-supplied values should always be passed as parameters, not
interpolated into the query string, where they form possible
<link linkend= "security.database.sql-injection" > SQL injection</link>
attack vectors and introduce bugs when handling data containing quotes.
If for some reason you cannot use a parameter, ensure that interpolated
values are <link linkend= "function.pg-escape-string" > properly escaped</link> .
</para>
2005-04-03 07:27:30 +00:00
</listitem>
</varlistentry>
<varlistentry >
<term > <parameter > params</parameter> </term>
2005-04-03 07:21:50 +00:00
<listitem >
2005-04-03 07:27:30 +00:00
<para >
2005-04-03 07:21:50 +00:00
An array of parameter values to substitute for the $1, $2, etc. placeholders
in the original prepared query string. The number of elements in the array
2005-04-03 07:27:30 +00:00
must match the number of placeholders.
</para>
2013-08-30 11:50:52 +00:00
<para >
Values intended for <literal > bytea</literal> fields are not supported as
parameters. Use <function > pg_escape_bytea</function> instead, or use the
large object functions.
</para>
2005-04-03 07:27:30 +00:00
</listitem>
</varlistentry>
</variablelist>
</para>
</refsect1>
<refsect1 role= "returnvalues" >
&reftitle.returnvalues;
<para >
2009-11-09 10:26:08 +00:00
A query result resource on success&return.falseforfailure; .</para>
2005-04-03 07:21:50 +00:00
</refsect1>
2005-03-20 08:54:31 +00:00
<refsect1 role= "examples" >
&reftitle.examples;
<para >
<example >
<title > Using <function > pg_query_params</function> </title>
<programlisting role= "php" >
< ![CDATA[
< ?php
// Connect to a database named "mary"
$dbconn = pg_connect("dbname=mary");
// Find all shops named Joe's Widgets. Note that it is not necessary to
// escape "Joe's Widgets"
$result = pg_query_params($dbconn, 'SELECT * FROM shops WHERE name = $1', array("Joe's Widgets"));
// Compare against just using pg_query
$str = pg_escape_string("Joe's Widgets");
$result = pg_query($dbconn, "SELECT * FROM shops WHERE name = '{$str}'");
?>
]]>
</programlisting>
</example>
</para>
</refsect1>
<refsect1 role= "seealso" >
&reftitle.seealso;
<para >
<simplelist >
<member > <function > pg_query</function> </member>
</simplelist>
</para>
</refsect1>
</refentry>
<!-- Keep this comment at the end of the file
Local variables:
mode: sgml
sgml-omittag:t
sgml-shorttag:t
sgml-minimize-attributes:nil
sgml-always-quote-attributes:t
sgml-indent-step:1
sgml-indent-data:t
indent-tabs-mode:nil
sgml-parent-document:nil
2009-09-25 07:04:39 +00:00
sgml-default-dtd-file:"~/.phpdoc/manual.ced"
2005-03-20 08:54:31 +00:00
sgml-exposed-tags:nil
sgml-local-catalogs:nil
sgml-local-ecat-files:nil
End:
vim600: syn=xml fen fdm=syntax fdl=2 si
vim: et tw=78 syn=sgml
vi: ts=1 sw=1
-->