如何将CF7文本表单标签值传入SQL查询的WHERE子句?
解决方法
要将CF7文本字段inputID的值传入SQL查询的WHERE子句,你需要使用CF7 Recordset插件的参数绑定语法,而非直接写字段名。修改后的代码如下:
[text inputID minlength:4 maxlength:19] [cf7-recordset id="cf7-recordset-918" type="database" dns="mysql:host=intranet.xxxxx.it;port=3306;dbname=xxxxxx_product_registration" username="xxxxxxx" password="xxxxxxx" query="SELECT * FROM wamblee_registration WHERE code = ?;" params="[inputID]"] [datatable datatable-419 recordset:cf7-recordset-918 autowidth ordering scrollx "Code|code" "Name|customer_name" "Surname|customer_surname" "Address|customer_address" "ZIP|customer_zip" "City|customer_city" "Country|customer_country" "Email|customer_email" "Phone|customer_phone1" "Phone|customer_phone2"] [submit "Submit"]
关键说明:
- 查询占位符:将原查询中的
inputID替换为?,这是参数绑定的标准占位符,用于安全传递变量。 - params参数:新增
params="[inputID]",这里的[inputID]对应你定义的文本字段短码,插件会自动将用户输入的字段值绑定到查询占位符上。 - 安全性:参数绑定方式能避免SQL注入风险,比直接拼接字符串更安全,是官方推荐的写法。
若你使用的插件版本支持直接引用字段值(不推荐,存在注入风险),也可以写成:
query="SELECT * FROM wamblee_registration WHERE code = '[inputID]';"
内容的提问来源于stack exchange,提问作者Daniele Banfi
相关产品推荐
相关产品推荐

