Advertisement

moodle_database::execute() Multiple sql statements found or bound parameters not used properly in query!


 

I will explain in storytelling, I have a table named "mdl_content" with 3 columns id, content, timecreated then i try to update data from content.

$DB->execute("UPDATE {content} SET content='this is content ! <>', timecreated='1672268400' WHERE id=1");
But what happens is we even get into trouble

Coding error detected, it must be fixed by a programmer: moodle_database::execute() Multiple sql statements found or bound parameters not used properly in query!

This happens because the system cannot input strings containing certain symbols like ! <> contained in the string that we will input.
So we have to create a filter and change the coding structure a bit.

	$content = 'this is content ! <>';

	$timecreated = '1672268400';

	$id = 1;

	//filtered strings
	$search = '/(<(?:lang|span) lang="[a-zA-Z0-9_-]*".*?>.+?<\/(?:lang|span)>)(\s*<(?:lang|span) lang="[a-zA-Z0-9_-]*".*?>.+?<\/(?:lang|span)>)+/is';
	$content = preg_replace_callback($search, 'multilangupgrade_impl', $content);

	//execute query
	$DB->execute("UPDATE {content} SET content=?, timecreated=? WHERE id=?",array($content,$timecreated,1));

Post a Comment

0 Comments