Remove filter_input from PDO example

This commit is contained in:
=
2012-07-16 17:25:27 -04:00
parent 040691ca99
commit f01b1b860b

View File

@@ -43,7 +43,7 @@ you should sanitize the ID input using PDO bound parameters.
<?php
$pdo = new PDO('sqlite:users.db');
$stmt = $pdo->prepare('SELECT name FROM users WHERE id = :id');
$stmt->bindParam(':id', filter_input(INPUT_GET, 'id', FILTER_SANITIZE_NUMBER_INT), PDO::PARAM_INT);
$stmt->bindParam(':id', $_GET['id'], PDO::PARAM_INT); //<-- Automatically sanitized by PDO
$stmt->execute();
{% endhighlight %}