<?php
include_once $_SERVER['DOCUMENT_ROOT'] . '/include/shared-manual.inc';
$TOC = array();
$TOC_DEPRECATED = array();
$PARENTS = array();
include_once dirname(__FILE__) ."/toc/mysqli.quickstart.inc";
$setup = array (
  'home' => 
  array (
    0 => 'index.php',
    1 => 'PHP Manual',
  ),
  'head' => 
  array (
    0 => 'UTF-8',
    1 => 'fr',
  ),
  'this' => 
  array (
    0 => 'mysqli.quickstart.multiple-statement.php',
    1 => 'Requ&ecirc;tes multiples',
    2 => 'Requ&ecirc;tes multiples',
  ),
  'up' => 
  array (
    0 => 'mysqli.quickstart.php',
    1 => 'Guide de d&eacute;marrage rapide',
  ),
  'prev' => 
  array (
    0 => 'mysqli.quickstart.stored-procedures.php',
    1 => 'Les proc&eacute;dures stock&eacute;es',
  ),
  'next' => 
  array (
    0 => 'mysqli.quickstart.transactions.php',
    1 => 'Support API pour les transactions',
  ),
  'alternatives' => 
  array (
  ),
  'source' => 
  array (
    'lang' => 'fr',
    'path' => 'reference/mysqli/quickstart.xml',
  ),
  'history' => 
  array (
  ),
);
$setup["toc"] = $TOC;
$setup["toc_deprecated"] = $TOC_DEPRECATED;
$setup["parents"] = $PARENTS;
manual_setup($setup);

contributors($setup);

?>
<div id="mysqli.quickstart.multiple-statement" class="section">
  <h2 class="title">Requêtes multiples</h2>
  <p class="para">
   MySQL autorise optionnellement le fait d&#039;avoir plusieurs requêtes dans une
   seule chaîne de requête mais nécessite une gestion spéciale.
  </p>
  <p class="para">
   Les requêtes multiples ou multirequêtes doivent être exécutées
   avec la fonction <span class="methodname"><a href="mysqli.multi-query.php" class="methodname">mysqli::multi_query()</a></span>. Les requêtes
   individuelles dans la chaîne de requête sont séparées par un point virgule.
   Ensuite, tous les jeux de résultats retournés par l&#039;exécution des requêtes
   doivent être récupérés.
  </p>
  <p class="para">
   Le serveur MySQL autorise d&#039;avoir des requêtes qui retournent des jeux
   de résultats ainsi que des requêtes qui ne retournent aucun jeu de résultats
   dans la même requête multiple.
  </p>
  <p class="para">
   <div class="example" id="example-1">
    <p><strong>Exemple #1 Requêtes multiples</strong></p>
    <div class="example-contents">
<div class="phpcode"><code><span style="color: #000000"><span style="color: #0000BB">&lt;?php<br /><br />mysqli_report</span><span style="color: #007700">(</span><span style="color: #0000BB">MYSQLI_REPORT_ERROR </span><span style="color: #007700">| </span><span style="color: #0000BB">MYSQLI_REPORT_STRICT</span><span style="color: #007700">);<br /></span><span style="color: #0000BB">$mysqli </span><span style="color: #007700">= new </span><span style="color: #0000BB">mysqli</span><span style="color: #007700">(</span><span style="color: #DD0000">"example.com"</span><span style="color: #007700">, </span><span style="color: #DD0000">"user"</span><span style="color: #007700">, </span><span style="color: #DD0000">"password"</span><span style="color: #007700">, </span><span style="color: #DD0000">"database"</span><span style="color: #007700">);<br /><br /></span><span style="color: #0000BB">$mysqli</span><span style="color: #007700">-&gt;</span><span style="color: #0000BB">query</span><span style="color: #007700">(</span><span style="color: #DD0000">"DROP TABLE IF EXISTS test"</span><span style="color: #007700">);<br /></span><span style="color: #0000BB">$mysqli</span><span style="color: #007700">-&gt;</span><span style="color: #0000BB">query</span><span style="color: #007700">(</span><span style="color: #DD0000">"CREATE TABLE test(id INT)"</span><span style="color: #007700">);<br /><br /></span><span style="color: #0000BB">$sql </span><span style="color: #007700">= </span><span style="color: #DD0000">"SELECT COUNT(*) AS _num FROM test;<br />        INSERT INTO test(id) VALUES (1); <br />        SELECT COUNT(*) AS _num FROM test; "</span><span style="color: #007700">;<br /><br /></span><span style="color: #0000BB">$mysqli</span><span style="color: #007700">-&gt;</span><span style="color: #0000BB">multi_query</span><span style="color: #007700">(</span><span style="color: #0000BB">$sql</span><span style="color: #007700">);<br /><br />do {<br />    if (</span><span style="color: #0000BB">$result </span><span style="color: #007700">= </span><span style="color: #0000BB">$mysqli</span><span style="color: #007700">-&gt;</span><span style="color: #0000BB">store_result</span><span style="color: #007700">()) {<br />        </span><span style="color: #0000BB">var_dump</span><span style="color: #007700">(</span><span style="color: #0000BB">$result</span><span style="color: #007700">-&gt;</span><span style="color: #0000BB">fetch_all</span><span style="color: #007700">(</span><span style="color: #0000BB">MYSQLI_ASSOC</span><span style="color: #007700">));<br />        </span><span style="color: #0000BB">$result</span><span style="color: #007700">-&gt;</span><span style="color: #0000BB">free</span><span style="color: #007700">();<br />    }<br />} while (</span><span style="color: #0000BB">$mysqli</span><span style="color: #007700">-&gt;</span><span style="color: #0000BB">next_result</span><span style="color: #007700">());</span></span></code></div>
    </div>

    <div class="example-contents"><p>L&#039;exemple ci-dessus va afficher :</p></div>
    <div class="example-contents screen">
<div class="cdata"><pre>
array(1) {
  [0]=&gt;
  array(1) {
    [&quot;_num&quot;]=&gt;
    string(1) &quot;0&quot;
  }
}
array(1) {
  [0]=&gt;
  array(1) {
    [&quot;_num&quot;]=&gt;
    string(1) &quot;1&quot;
  }
}
</pre></div>
    </div>
   </div>
  </p>
  <p class="para">
   <strong>D&#039;un point de vue de la sécurité</strong>
  </p>
  <p class="para">
   Les fonctions <span class="methodname"><a href="mysqli.query.php" class="methodname">mysqli::query()</a></span> et
   <span class="methodname"><a href="mysqli.real-query.php" class="methodname">mysqli::real_query()</a></span> de l&#039;API ne définissent pas de
   drapeau de connexion nécessaire pour l&#039;activation des multirequêtes sur
   le serveur. Un appel supplémentaire à l&#039;API est utilisé pour les multirequêtes
   pour réduire la probabilité d&#039;injection SQL accidentelle. Un attaquant peut
   tenter d&#039;ajouter des requêtes comme
   <code class="literal">; DROP DATABASE mysql</code> ou <code class="literal">; SELECT SLEEP(999)</code>.
   Si l&#039;attaquant arrive à ajouter ce genre de SQL dans la chaîne de requête
   mais que <span class="methodname"><a href="mysqli.multi-query.php" class="methodname">mysqli::multi_query()</a></span> n&#039;est pas utilisé, le serveur
   n&#039;exécutera que la première requête, mais pas la seconde représentant la requête SQL
   malicieuse.
  </p>
  <p class="para">
   <div class="example" id="example-2">
    <p><strong>Exemple #2 Injection SQL</strong></p>
    <div class="example-contents">
<div class="phpcode"><code><span style="color: #000000"><span style="color: #0000BB">&lt;?php<br /><br />mysqli_report</span><span style="color: #007700">(</span><span style="color: #0000BB">MYSQLI_REPORT_ERROR </span><span style="color: #007700">| </span><span style="color: #0000BB">MYSQLI_REPORT_STRICT</span><span style="color: #007700">);<br /></span><span style="color: #0000BB">$mysqli </span><span style="color: #007700">= new </span><span style="color: #0000BB">mysqli</span><span style="color: #007700">(</span><span style="color: #DD0000">"example.com"</span><span style="color: #007700">, </span><span style="color: #DD0000">"user"</span><span style="color: #007700">, </span><span style="color: #DD0000">"password"</span><span style="color: #007700">, </span><span style="color: #DD0000">"database"</span><span style="color: #007700">);<br /></span><span style="color: #0000BB">$result </span><span style="color: #007700">= </span><span style="color: #0000BB">$mysqli</span><span style="color: #007700">-&gt;</span><span style="color: #0000BB">query</span><span style="color: #007700">(</span><span style="color: #DD0000">"SELECT 1; DROP TABLE mysql.user"</span><span style="color: #007700">);</span></span></code></div>
    </div>

    <div class="example-contents"><p>L&#039;exemple ci-dessus va afficher :</p></div>
    <div class="example-contents screen">
<div class="cdata"><pre>
PHP Fatal error:  Uncaught mysqli_sql_exception: You have an error in your SQL syntax; 
check the manual that corresponds to your MySQL server version for the right syntax to 
use near &#039;DROP TABLE mysql.user&#039; at line 1
</pre></div>
    </div>
   </div>
  </p>
  <p class="para">
   <strong>Prepared statements</strong>
  </p>
  <p class="para">
   L&#039;utilisation des requêtes multiples avec des requêtes préparées n&#039;est pas supportée.
  </p>
  <p class="para">
   <strong>Voir aussi</strong>
  </p>
  <p class="para">
   <ul class="simplelist">
    <li><span class="methodname"><a href="mysqli.query.php" class="methodname">mysqli::query()</a></span></li>
    <li><span class="methodname"><a href="mysqli.multi-query.php" class="methodname">mysqli::multi_query()</a></span></li>
    <li><span class="methodname"><strong>mysqli_result::next-result()</strong></span></li>
    <li><span class="methodname"><strong>mysqli_result::more-results()</strong></span></li>
   </ul>
  </p>
 </div><?php manual_footer($setup); ?>