This is my code written as a prepared statement. What variable/word should I be putting in the places where I have question marks?? Any tips/feedback helps!
require_once "db.inc.php";
if($_REQUEST['name']) {
$myname = mysqli_real_escape_string($mysqli, $_REQUEST['name']);
$myprice = mysqli_real_escape_string($mysqli, $_REQUEST['price']);
$mysize = mysqli_real_escape_string($mysqli, $_REQUEST['size']);
$stmt = mysqli_prepare($mysqli, "INSERT INTO products (name, price, size ) VALUES (?, ?, ?)");
mysqli_stmt_bind_param($stmt, "sii", $myname, $myprice, $mysize );
mysqli_stmt_execute($stmt);
$result = mysqli_stmt_get_result($stmt);
$row= mysqli_fetch_array($result);
if(??????? === TRUE) {
echo "New product $myname created successfully!";
} else {
echo "Error: " .htmlentities(????) . "<br>" . $mysqli->error;
}
}