php - 使用准备好的语句时如何将参数传递给 "WHERE IN"查询?

标签 php mysql laravel pdo prepared-statement

我已经尝试解决这个问题好几天了,但似乎找不到解决方案。

我正在使用 Laravel 并尝试执行一个包含多个“WHERE”和“WHERE IN”子句的 Mysql 查询,但如果单个“WHERE IN”包含多个值,则查询会由于添加引号而失败围绕整个参数。

我将参数作为字符串传递。如果它包含一个值,它可以正常工作,但当它包含多个值时,它会失败。

$arrival_location = "PALMA"; // WORKS

$arrival_location = "PALMA, BEIJING"; // FAILS

我尝试了几种不同的方式传递参数,但没有成功。

北京帕尔马

“帕尔马”、“北京”

“‘帕尔马’,‘北京’”

这是查询...

$travel_data = DB::select(DB::raw('SELECT sd.FlightNumber, c1.Country as ArrivalCountry, c1.CityName as ArrivalCity, c2.Country as DepartureCountry, c2.CityName as DepartureCity, a.AirlineName, c1.LatDeg, c1.LonDeg, tp.emergency_name, tp.emergency_relation, tp.emergency_address_line_1, tp.emergency_address_line_2,tp.emergency_city, tp.emergency_country, tp.emergency_post_code, tp.emergency_landline_number, tp.emergency_mobile_number
FROM (SELECT max(PnrBfVersion) as pnrversion, TransactionsID, RecordLocator as recordlocator FROM transactions GROUP BY RecordLocator) as max
JOIN transactions t
ON max.pnrversion = t.PnrBfVersion AND max.recordlocator = t.RecordLocator
LEFT JOIN transaction_details td
ON t.TransactionsID = td.TransactionsID
LEFT JOIN segment_details sd
ON td.TransactionDetailsID = sd.TransactionDetailsID
LEFT JOIN cities c1
ON sd.ArrivalCityCode = c1.CityCode
LEFT JOIN cities c2
ON sd.DepartureCityCode = c2.CityCode
LEFT JOIN airlines a
ON sd.CarrierCode = a.AirlineCode
JOIN traveller_profiles tp
ON td.TravellerID = tp.id
WHERE TravellerID IN (SELECT id FROM traveller_profiles WHERE assigned_manager = ?)
AND TravelType = "10" AND transactionStatus = "T" # Air only and Ticketed data only
AND ArrivalInfo < ?
AND (tp.passenger_first_name LIKE ? OR tp.passenger_last_name LIKE ? OR c1.CityName IN (?) OR c1.Country IN (?) OR c2.CityName IN (?) OR c2.Country IN (?) OR FlightNumber IN (?) OR AirlineName IN (?))'),
array($user_id,
$to_date,
$search_query."%",
$search_query."%",
$arrival_location,
$arrival_country,
$departure_location,
$departure_country,
$flight_number,
$supplier));

检查 MySQL 日志时,我可以看到它在整个参数周围添加了引号。

AND (tp.passenger_first_name LIKE 'placeholder%' OR tp.passenger_last_name LIKE 'placeholder%' OR c1.CityName IN ('PALMA, BEIJING CAPITAL') OR c1.Country IN ('') OR c2.CityName IN ('') OR c2.Country IN ('') OR FlightNumber IN ('') OR AirlineName IN (''))

当添加我自己的引号时,它会在查询中添加斜杠...

AND (tp.passenger_first_name LIKE 'placeholder%' OR tp.passenger_last_name LIKE 'placeholder%' OR c1.CityName IN ('\'PALMA\', \'MALTA\'') OR c1.Country IN ('') OR c2.CityName IN ('') OR c2.Country IN ('') OR FlightNumber IN ('') OR AirlineName IN (''))

最佳答案

您不能传入单个参数并使其代表 SQL 语句中的列表。对于此查询,您可以替换:

c1.CityName IN (?)

与:

find_in_set(c1.CityName, ?) > 0

在某些情况下,这不是一个好主意,因为它会阻止索引的使用。在您的查询中,此 where 子句不太可能使用索引。

关于php - 使用准备好的语句时如何将参数传递给 "WHERE IN"查询?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/29491576/

相关文章:

c# - 通过标签加载图片

PhpStorm:有没有办法使用内联 PHPDoc 注释在 return 语句上强制执行类型?

jquery - Laravel DELETE 表单外请求 - 获取数据

mysql - 数据库访问权限模型

php从同一个类中的静态方法调用类方法但未实例化

php - Doctrine ORM : use interface as relation for different entities?

javascript - JS 函数仅在以管理员身份登录时显示/工作 [Wordpress]

mysql - 需要 MYSQL 查询仅选择特定子行

php - 根据 opencart 2 中的语言更改 Logo

php - 无法向表中插入数据