admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 1 | <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
Derek Allard | afd99ac | 2008-01-19 19:59:14 +0000 | [diff] [blame] | 2 | <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 3 | <head>
|
| 4 |
|
Derek Allard | 8039d4c | 2008-05-31 02:47:56 +0000 | [diff] [blame] | 5 | <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
|
Derek Jones | fd93d22 | 2008-05-06 15:18:50 +0000 | [diff] [blame] | 6 | <title>Queries : CodeIgniter User Guide</title>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 7 |
|
| 8 | <style type='text/css' media='all'>@import url('../userguide.css');</style>
|
| 9 | <link rel='stylesheet' type='text/css' media='all' href='../userguide.css' />
|
| 10 |
|
admin | 17a890d | 2006-09-27 20:42:42 +0000 | [diff] [blame] | 11 | <script type="text/javascript" src="../nav/nav.js"></script>
|
admin | 2296fc3 | 2006-09-27 21:07:02 +0000 | [diff] [blame] | 12 | <script type="text/javascript" src="../nav/prototype.lite.js"></script>
|
admin | 17a890d | 2006-09-27 20:42:42 +0000 | [diff] [blame] | 13 | <script type="text/javascript" src="../nav/moo.fx.js"></script>
|
Derek Allard | b341237 | 2007-10-25 12:15:16 +0000 | [diff] [blame] | 14 | <script type="text/javascript" src="../nav/user_guide_menu.js"></script>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 15 |
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 16 | <meta http-equiv='expires' content='-1' />
|
| 17 | <meta http-equiv= 'pragma' content='no-cache' />
|
| 18 | <meta name='robots' content='all' />
|
Derek Allard | 3d879d5 | 2008-01-18 19:41:32 +0000 | [diff] [blame] | 19 | <meta name='author' content='ExpressionEngine Dev Team' />
|
Derek Allard | d2df9bc | 2007-04-15 17:41:17 +0000 | [diff] [blame] | 20 | <meta name='description' content='CodeIgniter User Guide' />
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 21 |
|
| 22 | </head>
|
| 23 | <body>
|
| 24 |
|
| 25 | <!-- START NAVIGATION -->
|
| 26 | <div id="nav"><div id="nav_inner"><script type="text/javascript">create_menu('../');</script></div></div>
|
Rick Ellis | 7cdef03 | 2008-08-26 18:44:54 +0000 | [diff] [blame] | 27 | <div id="nav2"><a name="top"></a><a href="javascript:void(0);" onclick="myHeight.toggle();"><img src="../images/nav_toggle_darker.jpg" width="154" height="43" border="0" title="Toggle Table of Contents" alt="Toggle Table of Contents" /></a></div>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 28 | <div id="masthead">
|
| 29 | <table cellpadding="0" cellspacing="0" border="0" style="width:100%">
|
| 30 | <tr>
|
Rick Ellis | 2594953 | 2008-08-26 19:48:08 +0000 | [diff] [blame] | 31 | <td><h1>CodeIgniter User Guide Version 1.7</h1></td>
|
admin | c0d5d52 | 2006-10-30 19:40:35 +0000 | [diff] [blame] | 32 | <td id="breadcrumb_right"><a href="../toc.html">Table of Contents Page</a></td>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 33 | </tr>
|
| 34 | </table>
|
| 35 | </div>
|
| 36 | <!-- END NAVIGATION -->
|
| 37 |
|
| 38 |
|
| 39 | <!-- START BREADCRUMB -->
|
| 40 | <table cellpadding="0" cellspacing="0" border="0" style="width:100%">
|
| 41 | <tr>
|
| 42 | <td id="breadcrumb">
|
Derek Jones | 7a9193a | 2008-01-21 18:39:20 +0000 | [diff] [blame] | 43 | <a href="http://codeigniter.com/">CodeIgniter Home</a> ›
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 44 | <a href="../index.html">User Guide Home</a> ›
|
| 45 | <a href="index.html">Database Library</a> ›
|
| 46 | Queries
|
| 47 | </td>
|
Derek Allard | bc03091 | 2007-06-24 18:25:29 +0000 | [diff] [blame] | 48 | <td id="searchbox"><form method="get" action="http://www.google.com/search"><input type="hidden" name="as_sitesearch" id="as_sitesearch" value="codeigniter.com/user_guide/" />Search User Guide <input type="text" class="input" style="width:200px;" name="q" id="q" size="31" maxlength="255" value="" /> <input type="submit" class="submit" name="sa" value="Go" /></form></td>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 49 | </tr>
|
| 50 | </table>
|
| 51 | <!-- END BREADCRUMB -->
|
| 52 |
|
| 53 |
|
| 54 |
|
| 55 | <br clear="all" />
|
| 56 |
|
| 57 |
|
| 58 | <!-- START CONTENT -->
|
| 59 | <div id="content">
|
| 60 |
|
| 61 |
|
| 62 | <h1>Queries</h1>
|
| 63 |
|
| 64 | <h2>$this->db->query();</h2>
|
| 65 |
|
| 66 | <p>To submit a query, use the following function:</p>
|
| 67 |
|
| 68 | <code>$this->db->query('YOUR QUERY HERE');</code>
|
| 69 |
|
| 70 | <p>The <dfn>query()</dfn> function returns a database result <strong>object</strong> when "read" type queries are run,
|
| 71 | which you can use to <a href="results.html">show your results</a>. When "write" type queries are run it simply returns TRUE or FALSE
|
| 72 | depending on success or failure. When retrieving data you will typically assign the query to your own variable, like this:</p>
|
| 73 |
|
| 74 | <code><var>$query</var> = $this->db->query('YOUR QUERY HERE');</code>
|
| 75 |
|
| 76 | <h2>$this->db->simple_query();</h2>
|
| 77 |
|
| 78 | <p>This is a simplified version of the <dfn>$this->db->query()</dfn> function. It ONLY returns TRUE/FALSE on success or failure.
|
admin | e334c47 | 2006-10-21 19:44:22 +0000 | [diff] [blame] | 79 | It DOES NOT return a database result set, nor does it set the query timer, or compile bind data, or store your query for debugging.
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 80 | It simply lets you submit a query. Most users will rarely use this function.</p>
|
| 81 |
|
| 82 |
|
Derek Allard | 3b11868 | 2008-01-22 23:44:32 +0000 | [diff] [blame] | 83 | <h1>Adding Database prefixes manually</h1>
|
| 84 | <p>If you have configured a database prefix and would like to add it in manually for, you can use the following.</p>
|
| 85 | <p><code>$this->db->dbprefix('tablename');<br />
|
| 86 | // outputs prefix_tablename</code></p>
|
Derek Allard | 39b622d | 2008-01-16 21:10:09 +0000 | [diff] [blame] | 87 | <h1>Protecting identifiers</h1>
|
| 88 | <p>In many databases it is advisable to protect table and field names - for example with backticks in MySQL. Active Record queries are automatically protected, however if you need to manually protect an identifier you can use:</p>
|
Derek Jones | af368e1 | 2008-02-25 21:43:26 +0000 | [diff] [blame] | 89 | <p><code>$this->db->protect_identifiers('table_name');</code></p>
|
admin | 78ce3cc | 2006-10-02 02:58:03 +0000 | [diff] [blame] | 90 | <h1>Escaping Queries</h1>
|
admin | e334c47 | 2006-10-21 19:44:22 +0000 | [diff] [blame] | 91 | <p>It's a very good security practice to escape your data before submitting it into your database.
|
Derek Allard | d2df9bc | 2007-04-15 17:41:17 +0000 | [diff] [blame] | 92 | CodeIgniter has two functions that help you do this:</p>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 93 |
|
| 94 | <ol>
|
admin | e334c47 | 2006-10-21 19:44:22 +0000 | [diff] [blame] | 95 | <li><strong>$this->db->escape()</strong> This function determines the data type so that it
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 96 | can escape only string data. It also automatically adds single quotes around the data so you don't have to:
|
| 97 |
|
Derek Allard | c644128 | 2007-07-04 23:54:32 +0000 | [diff] [blame] | 98 | <code>$sql = "INSERT INTO table (title) VALUES(".$this->db->escape($title).")";</code></li>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 99 |
|
admin | e334c47 | 2006-10-21 19:44:22 +0000 | [diff] [blame] | 100 | <li><strong>$this->db->escape_str()</strong> This function escapes the data passed to it, regardless of type.
|
Derek Allard | cb36e34 | 2008-08-31 14:24:56 +0000 | [diff] [blame] | 101 | Most of the time you'll use the above function rather than this one. Use the function like this:
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 102 |
|
Derek Allard | c644128 | 2007-07-04 23:54:32 +0000 | [diff] [blame] | 103 | <code>$sql = "INSERT INTO table (title) VALUES('".$this->db->escape_str($title)."')";</code></li>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 104 | </ol>
|
| 105 |
|
| 106 |
|
admin | 78ce3cc | 2006-10-02 02:58:03 +0000 | [diff] [blame] | 107 | <h1>Query Bindings</h1>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 108 |
|
| 109 |
|
| 110 | <p>Bindings enable you to simplify your query syntax by letting the system put the queries together for you. Consider the following example:</p>
|
| 111 |
|
| 112 | <code>
|
| 113 | $sql = "SELECT * FROM some_table WHERE id = <var>?</var> AND status = <var>?</var> AND author = <var>?</var>";
|
| 114 | <br /><br />
|
| 115 | $this->db->query($sql, array(3, 'live', 'Rick'));
|
| 116 | </code>
|
| 117 |
|
| 118 | <p>The question marks in the query are automatically replaced with the values in the array in the second parameter of the query function.</p>
|
| 119 | <p class="important">The secondary benefit of using binds is that the values are automatically escaped, producing safer queries. You don't have to remember to manually escape data; the engine does it automatically for you.</p>
|
| 120 |
|
| 121 |
|
| 122 |
|
| 123 | </div>
|
| 124 | <!-- END CONTENT -->
|
| 125 |
|
| 126 |
|
| 127 | <div id="footer">
|
| 128 | <p>
|
| 129 | Previous Topic: <a href="connecting.html">Connecting to your Database</a>
|
| 130 | ·
|
| 131 | <a href="#top">Top of Page</a> ·
|
| 132 | <a href="../index.html">User Guide Home</a> ·
|
| 133 | Next Topic: <a href="results.html">Query Results</a>
|
Derek Allard | c644128 | 2007-07-04 23:54:32 +0000 | [diff] [blame] | 134 | </p>
|
Derek Jones | 0787043 | 2008-02-13 03:49:26 +0000 | [diff] [blame] | 135 | <p><a href="http://codeigniter.com">CodeIgniter</a> · Copyright © 2006-2008 · <a href="http://ellislab.com/">Ellislab, Inc.</a></p>
|
admin | fb28bb8 | 2006-09-24 17:59:33 +0000 | [diff] [blame] | 136 | </div>
|
| 137 |
|
| 138 | </body>
|
| 139 | </html> |