Database with PDO
| Connect with PDO | |
| SELECT and fetch | |
| INSERT with prepare | |
| Placeholders stop injections |
Connect with PDO
PDO is one interface for many databases. You build it with a DSN string - the database type, host, and name - plus a user and a password. Two options matter from day one: throw exceptions on errors, and fetch associative arrays by default.
$pdo = new PDO( "mysql:host=localhost;dbname=blog;charset=utf8mb4", "blog_user", "secret", [ PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION, PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC, ] );
SELECT and fetch
Queries that return rows come in two steps: ask, then fetch. query() runs plain SQL with no user input in it; the loop reads one row at a time, so large tables never flood memory.
$stmt = $pdo->query("SELECT id, title FROM posts ORDER BY id DESC"); foreach ($stmt as $row) { echo $row["title"] . "\n"; }
INSERT with prepare
The moment user input enters SQL, switch from query() to prepare() plus execute(). Values travel separately from the SQL text, so a quote in a name can never break out of its value.
$stmt = $pdo->prepare("INSERT INTO posts (title, body) VALUES (:title, :body)"); $stmt->execute([":title" => $title, ":body" => $body]); echo $pdo->lastInsertId();
Placeholders stop injections
A placeholder is a promise: this spot holds data, never code. The database compiles the statement first and plugs values in later, which is why injections fail by construction. Never concatenate input into SQL when a placeholder can carry it.
Connections, drivers, and practical details live under databases.
Next: Uploads and .htaccess
Article author: Arthur Isaev