· 10 years ago · Aug 20, 2016, 02:56 AM
1<?php
2// connection logic
3// ---------------------------------------------------
4
5// create an associative array of database parameters
6$db_params = [
7 'DB_NAME' => 'my_database',
8 'DB_HOST' => 'localhost',
9 'DB_USER' => 'username',
10 'DB_PASSWORD' => 'password',
11 'DB_DRIVER' => 'mysql'
12];
13
14// create dsn string for PDO
15// http://php.net/manual/en/pdo.construct.php
16// http://php.net/manual/en/function.sprintf.php
17$dsn = sprintf(
18 '%s:dbname=%s;host=%s',
19 $db_params['DB_DRIVER'],
20 $db_params['DB_NAME'],
21 $db_params['DB_HOST']
22);
23
24// always instantiate a variable outside a try/catch block
25$db = null;
26try {
27 // Here you're going to create a PDO object, which is the preferred
28 // way to handle DB connections in PHP. PDO is nice because it
29 // allows you to easily prepare and sanitize queries, and it also
30 // doesn't care too much about what type of database you use.
31 // http://php.net/manual/en/book.pdo.php
32 $db = new PDO($dsn, $db_params['DB_USER'], $db_params['DB_PASSWORD']);
33} catch (PDOException $ex) {
34 // this script will halt, but even if you don't want
35 // to handle the exception, you can be sure that $db
36 // has some value (null) so that PHP won't complain
37 die('Unable to connect: ' . $ex->getMessage());
38}
39// end connection logic
40// ---------------------------------------------------
41
42// First, prepare the query. You are using mysql, so use '?' for your
43// place holder (see below). Also, in mysql, it is always a best practice
44// to use backticks to wrap table and column names. This is because if you
45// had a table or column that was also the name of a reserved mysql word
46// (like the actual word "column" for example), mysql would know that you
47// mean the named thing and not the reserved word
48$sql = "INSERT INTO `users` (`user_name`, `user_password`, `user_email`) VALUES (?, ?, ?)";
49
50// also notice that we are just preparing the query...not executing it yet.
51// when we prepare a query, we are given a statement in return
52// One of the nice things about statements is that we can reuse them if we have
53// to perform the same query more than once
54// http://php.net/manual/en/pdo.prepare.php
55$statement = $db->prepare($sql)
56
57// Now we are going to handle our form inputs. I noticed you were using the
58// error suppression operator (@). You should avoid using this at all costs.
59// http://php.net/manual/en/language.operators.errorcontrol.php
60//
61// I am assuming that it was originally used to silence the error if the index
62// did not exist in the $_POST superglobal
63// http://php.net/manual/en/language.variables.superglobals.php
64//
65// A better way to check if something exists in an array is to use isset:
66// http://php.net/manual/en/function.isset.php
67//
68// Another shortcut is to use what's called a ternary operator to make a one-line
69// if/else statement.
70// http://php.net/manual/en/language.operators.comparison.php#language.operators.comparison.ternary
71// So here is how you handle the form inputs:
72$username = isset($_POST['username']) ? $_POST['username'] : '';
73$password = isset($_POST['password']) ? $_POST['password'] : '';
74$conf_password = isset($_POST['conf_password']) ? $_POST['conf_password'] : '';
75$email = isset($_POST['email']) ? $_POST['email'] : '';
76
77// check passwords
78if ($password !== $conf_password) {
79 // handle me
80}
81
82// It's also worth mentioning that you should never store passwords in plain text
83// If your PHP version is > 5.5 (which it should be), you should use the
84// password_hash function
85// http://php.net/manual/en/function.password-hash.php
86//
87// here we will hash the password if it has any length > 0
88if (strlen($password) > 0) {
89 $password = password_hash($password, PASSWORD_DEFAULT);
90}
91
92// so now we can execute the query
93// http://php.net/manual/en/pdostatement.execute.php
94$success = $statement->execute([
95 $username,
96 $password,
97 $email
98]);
99
100if ($success) {
101 echo 'YOU ARE A SUCCESS';
102}