My code has to update a query with a custom variable as column.
How can I safely bind the column name?
$username = 'MyUsername';
$rank = 'Administrator';
$server = 'Node5';
$stmt = $connection->prepare("UPDATE staff_members SET ?=? WHERE Username=? LIMIT 1");
$stmt->bind_param("sss", $server, $rank, $username);
$stmt->execute();
See Question&Answers more detail:
os 与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…