预准备语句 mysql/php 的语法错误


syntax error with prepared statements mysql/php

从昨晚开始就一直在搞这个,但无济于事。

createOrder($website,(int)$nVotes,(int)$timeframe,$loggedInUser->email,$server,(int)$start,$referer);

var_dumping这些变量显示(较早):

字符串(2) "web1" 字符串(2) "10" 字符串(

2) "10" 字符串(23) "myemail@gmail.com" 字符串(8) "我的服务器" int(1423063633) 字符串(17) "http://google.com"

似乎有问题的函数是:

function createOrder($website,$votes,$timeframe,$user,$server,$start,$referer)
{
    global $mysqli,$db_table_prefix;
    $time = time();
    $stmt = $mysqli->prepare("INSERT INTO ".$db_table_prefix."orders (
        serverId,
        orderUser,
        targetUrl,
        nVotes,
        timeframe,
        referer,
        starting
        )
        VALUES (
        ?,
        ?,
        ?,
        ?,
        ?,
        ?,
        ?
        )");
    file_put_contents("error.log", $mysqli->errno . $mysqli->error );
    $stmt->bind_param("sssiisi", $server, $user, $website, $votes, $timeframe, $referer, $start);
    file_put_contents("error1.log", $stmt->errno . $stmt->error );
    $stmt->execute();
    file_put_contents("error1.log", $stmt->errno . $stmt->error );
    $stmt->close(); 

nginx.error.log指责bind_param

"PHP 消息:PHP 致命错误:调用成员函数 bind_param() 在 funcs 中的非对象上.php在第 1223 行

错误.log归咎于语法错误

(check the manual) for the syntax to use near 'starting
  )
                VALUES (
                ?,
                ?,
                ?,
                ?,
                ?,
                ?,
                ?
                )' at line 8

问题是starting是MySQL中的保留字,并且您将其用作字段名称。您应该将其包装在反引号中:

    serverId,
    orderUser,
    targetUrl,
    nVotes,
    timeframe,
    referer,
    `starting`