Først og fremmest skal din PHP- eller HTML-side producere en formular, som brugeren kan interagere med. I den mest simple form ville det være noget som:
<form method="post" action="yourscript.php">
<input type="text" name="yourfield">
<input type="submit" name="youraction" value="save">
Dette vil give din bruger en simpel formular med et enkelt indtastningsfelt og 'gem'-knap. Efter at have klikket på 'gem'-knappen for indhold vil blive sendt til din 'dit script.php' ved hjælp af POST
bør implementere følgende:
- Accepter og bearbejd input fra din formular.
- Opret forbindelse til din MySQL-database.
- Gem i databasen.
I den mest forenklede form ville dette være:
<!doctype html>
<title>Process and store</title>
// Check that user sent some data to begin with.
if (isset($_REQUEST['yourfield'])) {
/* Sanitize input. Trust *nothing* sent by the client.
* When possible use whitelisting, only allow characters that you know
* are needed. If username must contain only alphanumeric characters,
* without puntation, then you should not accept anything else.
* For more details, see: https://stackoverflow.com/a/10094315
$yourfield=preg_replace('/[^a-zA-Z0-9\ ]/','',$_REQUEST['yourfield']);
/* Escape your input: use htmlspecialchars to avoid most obvious XSS attacks.
* Note: Your application may still be vulnerable to XSS if you use $yourfield
* in an attribute without proper quoting.
* For more details, see: https://stackoverflow.com/a/130323
} else {
die('User did not send any data to be saved!');
// Define MySQL connection and credentials
try {
// Establish connection to database
$conn = new PDO($pdo_dsn, $pdo_user, $pdo_password);
// Throw exceptions in case of error.
// Use prepared statements to mitigate SQL injection attacks.
// See https://stackoverflow.com/questions/60174/how-can-i-prevent-sql-injection-in-php for more details
$qry=$conn->prepare('INSERT INTO yourtable (yourcolumn) VALUES (:yourvalue)');
// Execute the prepared statement using user supplied data.
$qry->execute(Array(":yourvalue" => $yourfield));
} catch (PDOException $e) {
echo 'Error: ' . $e->getMessage() . " file: " . $e->getFile() . " line: " . $e->getLine();
<form method="post">
<!-- Please note that the quotes around next <?php ... ?> block are important
to avoid XSS issues with poorly escaped user input. For more details:
<input type="text" name="yourfield" value="<?php print $yourfield; ?>">
<input type="submit" name="youraction" value="save">
Det vigtigste her er at bruge forberedte erklæringer til undgå SQL-injektionsangreb .