<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <HTML ><HEAD ><TITLE >PDO->prepare()</TITLE ><META NAME="GENERATOR" CONTENT="Modular DocBook HTML Stylesheet Version 1.79"><LINK REL="HOME" TITLE="PHP 手册" HREF="index.html"><LINK REL="UP" TITLE="PDO Functions" HREF="ref.pdo.html"><LINK REL="PREVIOUS" TITLE="PDO->lastInsertId()" HREF="function.pdo-lastinsertid.html"><LINK REL="NEXT" TITLE="PDO->query()" HREF="function.pdo-query.html"><META HTTP-EQUIV="Content-type" CONTENT="text/html; charset=UTF-8"></HEAD ><BODY CLASS="refentry" BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#840084" ALINK="#0000FF" ><DIV CLASS="NAVHEADER" ><TABLE SUMMARY="Header navigation table" WIDTH="100%" BORDER="0" CELLPADDING="0" CELLSPACING="0" ><TR ><TH COLSPAN="3" ALIGN="center" >PHP 手册</TH ></TR ><TR ><TD WIDTH="10%" ALIGN="left" VALIGN="bottom" ><A HREF="function.pdo-lastinsertid.html" ACCESSKEY="P" >上一页</A ></TD ><TD WIDTH="80%" ALIGN="center" VALIGN="bottom" ></TD ><TD WIDTH="10%" ALIGN="right" VALIGN="bottom" ><A HREF="function.pdo-query.html" ACCESSKEY="N" >下一页</A ></TD ></TR ></TABLE ><HR ALIGN="LEFT" WIDTH="100%"></DIV ><H1 ><A NAME="function.PDO-prepare" ></A >PDO->prepare()</H1 ><DIV CLASS="refnamediv" ><A NAME="AEN176761" ></A ><P > (no version information, might be only in CVS)</P >PDO->prepare() -- Prepares a statement for execution and returns a statement object </DIV ><DIV CLASS="refsect1" ><A NAME="AEN176764" ></A ><H2 >说明</H2 >class <B CLASS="classname" >PDO</B > { <BR ></BR >PDOStatement <B CLASS="methodname" >prepare</B > ( string statement [, array driver_options] )<BR ></BR >}<P > Prepares an SQL statement to be executed by the <A HREF="function.pdostatement-execute.html" >PDOStatement->execute()</A > method. The SQL statement can contain zero or more named (:name) or question mark (?) parameter markers for which real values will be substituted when the statement is executed. You cannot use both named and question mark parameter markers within the same SQL statement; pick one or the other parameter style. </P ><P > You must include a unique parameter marker for each value you wish to pass in to the statement when you call <A HREF="function.pdostatement-execute.html" >PDOStatement->execute()</A >. You cannot use a named parameter marker of the same name twice in a prepared statement. You cannot bind multiple values to a single named parameter in, for example, the IN() clause of an SQL statement. </P ><P > Calling <A HREF="function.pdo-prepare.html" >PDO->prepare()</A > and <A HREF="function.pdostatement-execute.html" >PDOStatement->execute()</A > for statements that will be issued multiple times with different parameter values optimizes the performance of your application by allowing the driver to negotiate client and/or server side caching of the query plan and meta information, and helps to prevent SQL injection attacks by eliminating the need to manually quote the parameters. </P ><P > PDO will emulate prepared statements/bound parameters for drivers that do not natively support them, and can also rewrite named or question mark style parameter markers to something more appropriate, if the driver supports one style but not the other. </P ></DIV ><DIV CLASS="refsect1" ><A NAME="AEN176786" ></A ><H2 >参数</H2 ><P > <P ></P ><DIV CLASS="variablelist" ><DL ><DT ><CODE CLASS="parameter" >statement</CODE ></DT ><DD ><P > This must be a valid SQL statement for the target database server. </P ></DD ><DT ><CODE CLASS="parameter" >driver_options</CODE ></DT ><DD ><P > This array holds one or more key=>value pairs to set attribute values for the PDOStatement object that this method returns. You would most commonly use this to set the <TT CLASS="literal" >PDO::ATTR_CURSOR</TT > value to <TT CLASS="literal" >PDO::CURSOR_SCROLL</TT > to request a scrollable cursor. Some drivers have driver specific options that may be set at prepare-time. </P ></DD ></DL ></DIV > </P ></DIV ><DIV CLASS="refsect1" ><A NAME="AEN176802" ></A ><H2 >返回值</H2 ><P > If the database server successfully prepares the statement, <A HREF="function.pdo-prepare.html" >PDO->prepare()</A > returns a PDOStatement object. If the database server cannot successfully prepare the statement, <A HREF="function.pdo-prepare.html" >PDO->prepare()</A > returns <TT CLASS="constant" ><B >FALSE</B ></TT >. </P ></DIV ><DIV CLASS="refsect1" ><A NAME="AEN176808" ></A ><H2 >范例</H2 ><P > <TABLE WIDTH="100%" BORDER="0" CELLPADDING="0" CELLSPACING="0" CLASS="EXAMPLE" ><TR ><TD ><DIV CLASS="example" ><A NAME="AEN176811" ></A ><P ><B >例 1. Prepare an SQL statement with named parameters</B ></P ><TABLE BORDER="0" BGCOLOR="#E0E0E0" CELLPADDING="5" ><TR ><TD ><code><font color="#000000"> <font color="#0000BB"><?php<br /></font><font color="#FF8000">/* Execute a prepared statement by passing an array of values */<br /></font><font color="#0000BB">$sql </font><font color="#007700">= </font><font color="#DD0000">'SELECT name, colour, calories<br /> FROM fruit<br /> WHERE calories < :calories AND colour = :colour'</font><font color="#007700">;<br /></font><font color="#0000BB">$sth </font><font color="#007700">= </font><font color="#0000BB">$dbh</font><font color="#007700">-></font><font color="#0000BB">prepare</font><font color="#007700">(</font><font color="#0000BB">$sql</font><font color="#007700">, array(</font><font color="#0000BB">PDO</font><font color="#007700">::</font><font color="#0000BB">ATTR_CURSOR </font><font color="#007700">=> </font><font color="#0000BB">PDO</font><font color="#007700">::</font><font color="#0000BB">CURSOR_FWDONLY</font><font color="#007700">));<br /></font><font color="#0000BB">$sth</font><font color="#007700">-></font><font color="#0000BB">execute</font><font color="#007700">(array(</font><font color="#DD0000">':calories' </font><font color="#007700">=> </font><font color="#0000BB">150</font><font color="#007700">, </font><font color="#DD0000">':colour' </font><font color="#007700">=> </font><font color="#DD0000">'red'</font><font color="#007700">));<br /></font><font color="#0000BB">$red </font><font color="#007700">= </font><font color="#0000BB">$sth</font><font color="#007700">-></font><font color="#0000BB">fetchAll</font><font color="#007700">();<br /></font><font color="#0000BB">$sth</font><font color="#007700">-></font><font color="#0000BB">execute</font><font color="#007700">(array(</font><font color="#DD0000">'calories' </font><font color="#007700">=> </font><font color="#0000BB">175</font><font color="#007700">, </font><font color="#DD0000">'colour' </font><font color="#007700">=> </font><font color="#DD0000">'yellow'</font><font color="#007700">));<br /></font><font color="#0000BB">$yellow </font><font color="#007700">= </font><font color="#0000BB">$sth</font><font color="#007700">-></font><font color="#0000BB">fetchAll</font><font color="#007700">();<br /></font><font color="#0000BB">?></font> </font> </code></TD ></TR ></TABLE ></DIV ></TD ></TR ></TABLE > <TABLE WIDTH="100%" BORDER="0" CELLPADDING="0" CELLSPACING="0" CLASS="EXAMPLE" ><TR ><TD ><DIV CLASS="example" ><A NAME="AEN176814" ></A ><P ><B >例 2. Prepare an SQL statement with question mark parameters</B ></P ><TABLE BORDER="0" BGCOLOR="#E0E0E0" CELLPADDING="5" ><TR ><TD ><code><font color="#000000"> <font color="#0000BB"><?php<br /></font><font color="#FF8000">/* Execute a prepared statement by passing an array of values */<br /></font><font color="#0000BB">$sth </font><font color="#007700">= </font><font color="#0000BB">$dbh</font><font color="#007700">-></font><font color="#0000BB">prepare</font><font color="#007700">(</font><font color="#DD0000">'SELECT name, colour, calories<br /> FROM fruit<br /> WHERE calories < ? AND colour = ?'</font><font color="#007700">);<br /></font><font color="#0000BB">$sth</font><font color="#007700">-></font><font color="#0000BB">execute</font><font color="#007700">(array(</font><font color="#0000BB">150</font><font color="#007700">, </font><font color="#DD0000">'red'</font><font color="#007700">));<br /></font><font color="#0000BB">$red </font><font color="#007700">= </font><font color="#0000BB">$sth</font><font color="#007700">-></font><font color="#0000BB">fetchAll</font><font color="#007700">();<br /></font><font color="#0000BB">$sth</font><font color="#007700">-></font><font color="#0000BB">execute</font><font color="#007700">(array(</font><font color="#0000BB">175</font><font color="#007700">, </font><font color="#DD0000">'yellow'</font><font color="#007700">));<br /></font><font color="#0000BB">$yellow </font><font color="#007700">= </font><font color="#0000BB">$sth</font><font color="#007700">-></font><font color="#0000BB">fetchAll</font><font color="#007700">();<br /></font><font color="#0000BB">?></font> </font> </code></TD ></TR ></TABLE ></DIV ></TD ></TR ></TABLE > </P ></DIV ><DIV CLASS="refsect1" ><A NAME="AEN176817" ></A ><H2 >参见</H2 ><P > <P ></P ><TABLE BORDER="0" ><TBODY ><TR ><TD ><A HREF="function.pdo-exec.html" >PDO->exec()</A ></TD ></TR ><TR ><TD ><A HREF="function.pdo-query.html" >PDO->query()</A ></TD ></TR ><TR ><TD ><A HREF="function.pdostatement-execute.html" >PDOStatement->execute()</A ></TD ></TR ></TBODY ></TABLE ><P ></P > </P ></DIV ><DIV CLASS="NAVFOOTER" ><HR ALIGN="LEFT" WIDTH="100%"><TABLE SUMMARY="Footer navigation table" WIDTH="100%" BORDER="0" CELLPADDING="0" CELLSPACING="0" ><TR ><TD WIDTH="33%" ALIGN="left" VALIGN="top" ><A HREF="function.pdo-lastinsertid.html" ACCESSKEY="P" >上一页</A ></TD ><TD WIDTH="34%" ALIGN="center" VALIGN="top" ><A HREF="index.html" ACCESSKEY="H" >起始页</A ></TD ><TD WIDTH="33%" ALIGN="right" VALIGN="top" ><A HREF="function.pdo-query.html" ACCESSKEY="N" >下一页</A ></TD ></TR ><TR ><TD WIDTH="33%" ALIGN="left" VALIGN="top" >PDO->lastInsertId()</TD ><TD WIDTH="34%" ALIGN="center" VALIGN="top" ><A HREF="ref.pdo.html" ACCESSKEY="U" >上一级</A ></TD ><TD WIDTH="33%" ALIGN="right" VALIGN="top" >PDO->query()</TD ></TR ></TABLE ></DIV ></BODY ></HTML >