$link = create_connection();
try {
$stmt = $link->prepare("UPDATE repair_event SET signimg=:signimg where uid=:id");
$stmt->bindParam(':signimg',$signimg);
$stmt->bindParam(':id',$id);
$result = $stmt->execute();
if ($stmt->errorCode()[0]!="00000"){
echo "有錯誤!有錯誤!";
print_r($stmt->errorInfo());
}
// $stmt->debugDumpParams();
}
catch (PDOException $e) {
print $e->getMessage();
}
如果是select的話 以前是
$sql = "SELECT * FROM XXX WHERE username='".$account."' AND password='".$password."'";
$resultN = $link->query($sql);
要改為
$sql = "SELECT * FROM xxx WHERE username= :account AND password= :password";
$statement = $link->prepare($sql); /
$statement->execute(array(
'account' => $account,
'password' => $password
));
$Qrows=$statement->fetchALL(PDO::FETCH_ASSOC);
if ($statement->rowCount() != 0){
foreach ($Qrows as $rows) {
//XXX
}
}else{
//帳密錯誤
}