File: pg-select.xml

package info (click to toggle)
php-doc 20250827~git.abe740d%2Bdfsg-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 71,968 kB
  • sloc: xml: 985,760; php: 25,504; javascript: 671; sh: 177; makefile: 37
file content (210 lines) | stat: -rw-r--r-- 7,029 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
<?xml version="1.0" encoding="utf-8"?>
<!-- $Revision$ -->
<!-- splitted from ./en/functions/pgsql.xml, last change in rev 1.80 -->
<refentry xml:id="function.pg-select" xmlns="http://docbook.org/ns/docbook">
 <refnamediv>
  <refname>pg_select</refname>
  <refpurpose>
   Select records
  </refpurpose>
 </refnamediv>

 <refsect1 role="description">
  &reftitle.description;
  <methodsynopsis>
   <type class="union"><type>array</type><type>string</type><type>false</type></type><methodname>pg_select</methodname>
   <methodparam><type>PgSql\Connection</type><parameter>connection</parameter></methodparam>
   <methodparam><type>string</type><parameter>table_name</parameter></methodparam>
   <methodparam choice="opt"><type>array</type><parameter>conditions</parameter><initializer>[]</initializer></methodparam>
   <methodparam choice="opt"><type>int</type><parameter>flags</parameter><initializer><constant>PGSQL_DML_EXEC</constant></initializer></methodparam>
   <methodparam choice="opt"><type>int</type><parameter>mode</parameter><initializer><constant>PGSQL_ASSOC</constant></initializer></methodparam>
  </methodsynopsis>
  <para>
   <function>pg_select</function> selects records specified by
   <parameter>conditions</parameter> which has
   <literal>field=&gt;value</literal>. For a successful query, it returns an
   array containing all records and fields that match the condition
   specified by <parameter>conditions</parameter>.
  </para>
  <para>
   If <parameter>flags</parameter> is set,
   <function>pg_convert</function> is applied to
   <parameter>conditions</parameter> with the specified flags.
  </para>
  <para>
   If <parameter>mode</parameter> is set,
   the return value will be in the form of an array
   with <constant>PGSQL_NUM</constant>, an associative array
   with <constant>PGSQL_ASSOC</constant> (default) or both
   with <constant>PGSQL_BOTH</constant>.
  </para>
  <para>
   By default <function>pg_select</function> passes raw values. Values
   must be escaped or PGSQL_DML_ESCAPE option must be
   specified. PGSQL_DML_ESCAPE quotes and escapes
   parameters/identifiers. Therefore, table/column names became case
   sensitive.
  </para>
  <para>
   Note that neither escape nor prepared query can protect LIKE query,
   JSON, Array, Regex, etc. These parameters should be handled
   according to their contexts. i.e. Escape/validate values.
  </para>
 </refsect1>

  <refsect1 role="parameters">
   &reftitle.parameters;
   <para>
    <variablelist>
     <varlistentry>
      <term><parameter>connection</parameter></term>
      <listitem>
       &pgsql.parameter.connection;
      </listitem>
     </varlistentry>
     <varlistentry>
      <term><parameter>table_name</parameter></term>
      <listitem>
       <para>
        Name of the table from which to select rows.
       </para>
      </listitem>
     </varlistentry>
     <varlistentry>
      <term><parameter>conditions</parameter></term>
      <listitem>
       <para>
        An <type>array</type> whose keys are field names in the table <parameter>table_name</parameter>,
        and whose values are the conditions that a row must meet to be retrieved.
        As of PHP 8.4.0, when an empty array is provided, no conditions will apply.
        Previously, the function failed with an empty <parameter>conditions</parameter> argument.
       </para>
      </listitem>
     </varlistentry>
     <varlistentry>
      <term><parameter>flags</parameter></term>
      <listitem>
       <para>
        Any number of <constant>PGSQL_CONV_FORCE_NULL</constant>,
        <constant>PGSQL_DML_NO_CONV</constant>,
        <constant>PGSQL_DML_ESCAPE</constant>,
        <constant>PGSQL_DML_EXEC</constant>,
        <constant>PGSQL_DML_ASYNC</constant> or
        <constant>PGSQL_DML_STRING</constant> combined. If <constant>PGSQL_DML_STRING</constant> is part of the
        <parameter>flags</parameter> then the query string is returned. When <constant>PGSQL_DML_NO_CONV</constant>
        or <constant>PGSQL_DML_ESCAPE</constant> is set, it does not call <function>pg_convert</function> internally.
       </para>
      </listitem>
     </varlistentry>
     <varlistentry>
      <term><parameter>mode</parameter></term>
      <listitem>
       <para>
        Any number of <constant>PGSQL_ASSOC</constant>,
        <constant>PGSQL_NUM</constant> or
        <constant>PGSQL_BOTH</constant>
        If <constant>PGSQL_ASSOC</constant> is set the return value will be an associative <type>array</type>,
        with <constant>PGSQL_NUM</constant> the return value will be an <type>array</type>, and
        with <constant>PGSQL_BOTH</constant> the return value will be both an associative and
        numerically indexed <type>array</type>.
      </para>
     </listitem>
    </varlistentry>
   </variablelist>
  </para>
 </refsect1>

 <refsect1 role="returnvalues">
  &reftitle.returnvalues;
  <para>
   Returns <type>string</type> if <constant>PGSQL_DML_STRING</constant> is passed
   via <parameter>flags</parameter>, otherwise it returns an <type>array</type> on success, &return.falseforfailure;.
  </para>
 </refsect1>

 <refsect1 role="changelog">
  &reftitle.changelog;
  <para>
   <informaltable>
    <tgroup cols="2">
     <thead>
      <row>
       <entry>&Version;</entry>
       <entry>&Description;</entry>
      </row>
     </thead>
     <tbody>
      <row>
       <entry>8.4.0</entry>
       <entry>
        <parameter>conditions</parameter> is now optional.
       </entry>
      </row>
      &pgsql.changelog.connection-object;
      <row>
       <entry>7.1.0</entry>
       <entry>
        The <parameter>mode</parameter> parameter was added.
       </entry>
      </row>
     </tbody>
    </tgroup>
   </informaltable>
  </para>
 </refsect1>

 <refsect1 role="examples">
  &reftitle.examples;
  <para>
   <example>
    <title><function>pg_select</function> example</title>
    <programlisting role="php">
     <![CDATA[
<?php 
  $db = pg_connect('dbname=foo');
  // This is safe somewhat, since all values are escaped.
  // However PostgreSQL supports JSON/Array. These are not
  // safe by neither escape nor prepared query.
  $rec = pg_select($db, 'post_log', $_POST, PG_DML_ESCAPE);
  if ($rec) {
      echo "Records selected\n";
      var_dump($rec);
  } else {
      echo "User must have sent wrong inputs\n";
  }
?>
]]>
    </programlisting>
   </example>
  </para>
 </refsect1>

 <refsect1 role="seealso">
  &reftitle.seealso;
  <para>
   <simplelist>
    <member><function>pg_convert</function></member>
   </simplelist>
  </para>
 </refsect1>
</refentry>
<!-- Keep this comment at the end of the file
Local variables:
mode: sgml
sgml-omittag:t
sgml-shorttag:t
sgml-minimize-attributes:nil
sgml-always-quote-attributes:t
sgml-indent-step:1
sgml-indent-data:t
indent-tabs-mode:nil
sgml-parent-document:nil
sgml-default-dtd-file:"~/.phpdoc/manual.ced"
sgml-exposed-tags:nil
sgml-local-catalogs:nil
sgml-local-ecat-files:nil
End:
vim600: syn=xml fen fdm=syntax fdl=2 si
vim: et tw=78 syn=sgml
vi: ts=1 sw=1
-->