PHP Knowledge Base

Simple Prepared Statement

$servername = "localhost";
$username = "hansolo";
$password = "falcon";
$whichTable = "users";

try {
    $conn = new PDO("mysql:host=$servername;dbname=FAKE__DB", $username, $password);
    // set the PDO error mode to exception
    $conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
        
    if (isset($_POST['submit']))
	{
		$php__username = $_POST['form__username'];
		$php__password = $_POST['form__password'];
		
		$query = "INSERT INTO $whichTable (username, password) 
		VALUES(:username,:password)";
		$statement = $conn->prepare($query);
		$statement->execute([
		'username' => $php__username,
		'password' => $php__password
		]);
	}
}
catch(PDOException $e)
    {
    echo "Connection failed: " . $e->getMessage();
}