PDO 的查询与执行

2021-12-26 00:00:00 php pdo


Are they both do the same thing, only differently?

$sth = $db->query("SELECT * FROM table");
$result = $sth->fetchAll();

$sth = $db->prepare("SELECT * FROM table");
$result = $sth->fetchAll();



query 运行标准的 SQL 语句并要求您正确转义所有数据以避免 SQL 注入和其他问题.

query runs a standard SQL statement and requires you to properly escape all data to avoid SQL Injections and other issues.

execute 运行准备好的语句,它允许您绑定参数以避免需要转义或引用参数.如果您多次重复查询,execute 也会表现得更好.准备好的语句示例:

execute runs a prepared statement which allows you to bind parameters to avoid the need to escape or quote the parameters. execute will also perform better if you are repeating a query multiple times. Example of prepared statements:

$sth = $dbh->prepare('SELECT name, colour, calories FROM fruit
    WHERE calories < :calories AND colour = :colour');
$sth->bindParam(':calories', $calories);
$sth->bindParam(':colour', $colour);
// $calories or $color do not need to be escaped or quoted since the
//    data is separated from the query


Best practice is to stick with prepared statements and execute for increased security.

另见:PDO 准备好的语句是否足以防止 SQL注射?
