PHP PDO Query Guide: Secure Data Retrieval
When querying data using PDO, you can follow these steps:
- Connect to the database.
$servername = "localhost";
$username = "root";
$password = "";
$dbname = "database_name";
try {
$conn = new PDO("mysql:host=$servername;dbname=$dbname", $username, $password);
$conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
echo "Connected successfully";
} catch(PDOException $e) {
echo "Connection failed: " . $e->getMessage();
}
- Write SQL query:
$sql = "SELECT * FROM table_name";
- Prepare and execute the query statement.
$stmt = $conn->prepare($sql);
$stmt->execute();
- Obtain search results:
$result = $stmt->fetchAll(PDO::FETCH_ASSOC);
- Handle search results:
foreach($result as $row) {
echo $row['column_name'];
}
The complete example code is as follows:
$servername = "localhost";
$username = "root";
$password = "";
$dbname = "database_name";
try {
$conn = new PDO("mysql:host=$servername;dbname=$dbname", $username, $password);
$conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
echo "Connected successfully";
$sql = "SELECT * FROM table_name";
$stmt = $conn->prepare($sql);
$stmt->execute();
$result = $stmt->fetchAll(PDO::FETCH_ASSOC);
foreach($result as $row) {
echo $row['column_name'];
}
} catch(PDOException $e) {
echo "Connection failed: " . $e->getMessage();
}
Please replace $servername, $username, $password, and $dbname with the actual database connection information. Also, replace table_name and column_name with the real table name and column name.