Heads up! To view this whole video, sign in with your Courses account or enroll in your free 7-day trial. Sign In Enroll

- 2x 2x
- 1.75x 1.75x
- 1.5x 1.5x
- 1.25x 1.25x
- 1.1x 1.1x
- 1x 1x
- 0.75x 0.75x
- 0.5x 0.5x
Whenever a piece of code receives input from somewhere else, whether that's directly from a site visitor or from code dealing with another concern, you want to filter or sanitize that input. We’ll use the built in PDO functionality to filter input as well, it is called a prepared statement.
Links
Documentation: PDO::prepare
Documentation: PDOStatement Class
Documentation: bindParam
Example Code
try {
$results = $db->prepare(
"SELECT title, category, img, format, year,
publisher, isbn, genre
FROM Media
JOIN Genres ON Media.genre_id=Genres.genre_id
LEFT OUTER JOIN Books
ON Media.media_id = Books.media_id
WHERE Media.media_id = ?"
);
$results->bindParam(1,$id,PDO::PARAM_INT);
$results->execute();
} catch (Exception $e) {
echo "bad query";
echo $e;
}
$item = $results->fetch(PDO::FETCH_ASSOC);
Related Discussions
Have questions about this video? Start a discussion with the community and Treehouse staff.
Sign up-
Anthony Meyer
2,472 Points1 Answer
-
Anna Róza Sávolyi
8,550 Points1 Answer
-
Jeff Styles
2,784 Points0 Answers
-
Hashim Amun
3,434 PointsWhy PDO STR string in Preparing SQL Statements Bind Param?
Posted by Hashim AmunHashim Amun
3,434 Points2 Answers
-
Alex Flores
7,864 PointsConfused on _GET and _POST when querying data from PHP?
Posted by Alex FloresAlex Flores
7,864 Points0 Answers
-
Daniel Malek
20,140 Points1 Answer
-
tomsteward
550 Points1 Answer
View all discussions for this video
Related Discussions
Have questions about this video? Start a discussion with the community and Treehouse staff.
Sign up
You need to sign up for Treehouse in order to download course files.
Sign upYou need to sign up for Treehouse in order to set up Workspace
Sign up