请问 php 这样操作数据库稳(安全)吗?,并发不大,体验要求也不高,百来人(使用人数),如果行的话,我就要开始咯。
function db_conn($sql) {
$SqlConn = new PDO("mysql:host=localhost;dbname=test", "root", "ll1314");
$SqlConn->setAttribute(PDO::ATTR_EMULATE_PREPARES, false);
$IsQuery = $SqlConn->prepare(array_shift(($sql)));
$IsChange=$IsQuery->execute($sql);
$ArrayResult = $IsQuery->fetchAll();
return !empty($ArrayResult)?$ArrayResult:$IsChange;
}
$sql=Array("select * from isuser where uid=?","42");
//$sql=Array("INSERT INTO `test`.`isuser`(`user`, `passwd`, `nickname`) VALUES (?, ?, ?)","testUser","pass","iamverylovely");
var_dump(db_conn($sql));