3 ms·
I'll be honest. I really don't like PHP. However when I was running a coding workshop, very frequently people would ask: "How do I make a web page talk to a da
by cjdell 5y ago
I'll be honest. I really don't like PHP. However when I was running a coding workshop, very frequently people would ask:
"How do I make a web page talk to a database?"
I'd say: Well, you know that HTML file? Rename it to become a PHP file and you're almost there!
As pretty much all cheap hosting already offers support for PHP (and MySQL for that matter) this would almost always work.
I would love to be able to do this with NodeJS, but imagine teaching that to an absolute beginner. The conversation would have to begin with hosting platforms / SSH / server management / reverse proxies etc....
- dexen 5y agoPHP: the original progressive enhancement.
- patates 5y agoIt's still far behind PHP[0], but with Next.js/blitz.js I think we're going in the right direction. [0]: as in, I would have nightmares trying to introduce beginners to full JS stack vs I would have nightmares thinking what they will end up coding when they easily become dangerous with PHP (which is I guess why there are so many bad PHP codebases: it's super easy to start)
- npteljes 5y agoYou hit the nail on the head, this is exactly why I fell in love with PHP. I learnt it back in the PHP4 days, and it just seemed like the perfectly straightforward way to do web. In a similar fashion, I abstracted away the database connection, query and returning of results into one lazy-inited function, so talking to the database really was just like <?=q("select name from users where id = $userid") ?> I worked a lot with other languages, none feeling as natural to me as this one, aside from Ruby.
- gbba 5y agoBe careful as this syntax can potentially introduce SQL injections. PHP's parameterization features in PDO can be abstracted so you can turn this into: $vars = array(":userid" => $userid); q("select name from users where id = :userid", $vars); It's still pretty concise and is much safer.
- dexen 5y agoTwo further alternatives for improved expressiveness: q('select name from users where id = :userid', compact('userid')); q('select name from users where id = ?', [ $userid ]); Recommend using single quotes for SQL (command) literals, rather than doublequotes. This helps with discouraging string interpolation (" ... WHERE col = $value "). This also helps very much with SQL quoting object names (tables, columns, indexes, etc) - SQL specifies doublequote (") as the quoting character; for example 'SELECT COUNT(users.id) AS "Number of users" FROM users', or 'CREATE VIEW "My daily report" AS SELECT SUM("count") FROM "some strange table" LEFT JOIN ...'.
- pitay 5y agoParameterized queries and statements are great. They solve problems where the paramaterized queries are used. However care must be taken, a script running on the database after information has been entered can still inject long after the initial parameterized statement put it into the database if that script itself does not use parameterized queries, making a SQL injection still work, in a delayed way.
- stemc43 5y agoYou need to try swoole/ openswoole - it brings golang style concurrency to php. you dont need to use nginx/apache and it beats node in performance tests. https://www.swoole.co.uk/ https://www.swoole.co.uk/