diff --git a/b1-bak/session2/blog/admin.php b/b1-bak/session2/blog/admin.php
index 51463df..d5e8893 100644
--- a/b1-bak/session2/blog/admin.php
+++ b/b1-bak/session2/blog/admin.php
@@ -42,15 +42,22 @@
echo "
Il manque quelque chose !
";
}
elseif(!empty($titre_de_article)) {
- $resultat = $mysqli->query("
- INSERT INTO `article` (`id_article`, `titre`, `contenu`, `date`)
- VALUES (NULL, '".$titre_de_article."', '".$contenu_de_article." ', NOW());
- ");
+ $sql = "INSERT INTO `article` (`id_article`, `titre`, `contenu`, `date`)
+ VALUES (NULL, ?, ?, NOW()); ";
+ $requete = $mysqli->prepare($sql);
+ //https://www.php.net/manual/en/mysqli-stmt.bind-param.php
+ $requete->bind_param('ss',$titre_de_article,$contenu_de_article);
+ $resultat = $requete->execute();
+
if($resultat) {
echo "Article enregistré !
";
$titre_de_article = "";
$contenu_de_article = "";
}
+ else {
+ echo "Error description: " . $mysqli -> error;
+ echo $sql;
+ }
}
?>