PHP for real applications
Practice PHP through PDO, authorization, JSON contracts, streams, and CSV. Diagnose serialization errors, incremental reading, and partial application failures.
Objectives and progression
Eight lessons, 60 regular questions, and 14 original scenarios connect PHP to applications and production support. New lessons teach JSON boundaries, textual identity, exceptions, CSV, generators, and resource ownership. Labs and fixtures distinguish behavior executed on PHP 8.3.17 from documentation notes about PHP 8.4 and 8.5. Examples are fictional and do not represent bank procedures. The final assessment reuses 44 decisions in 75 minutes. Further deepening, validation on runtime 8.5, and independent review remain pending.
Audience: Developers and support teams maintaining PHP applications and database integrations.
Prerequisites: Familiarity with variables, functions, HTTP, and SQL tables. Exercises include necessary assumptions.
328 estimated study minutes
- Distinguish coercion, domain validation, absence, and null.
- Build queries with parameters and resource authorization.
- Apply password verification and context-specific output encoding.
- Assess transactions, idempotency, and external-effect recovery.
- Separate JSON syntax, shape, identity, and business rules without data-losing coercion.
- Diagnose deferred exceptions, memory accumulation, and resource ownership in incremental readers.
- Validate CSV contracts and handle partial writes using acknowledged byte counts.
Modules
- Explicit types and comparisons
- Intentional arrays and functions
- Data with parameters
- Security at the web boundary
- PDO transactions and partial failures
- HTTP, sessions, and per-resource authorization
- JSON, contracts, and explicit failures
- Streams, CSV, and controlled imports
Continue learning
References and version
PHP 8.5 reference; DR PHP 2026.2; new fixtures executed on PHP 8.3.17
- PHP manual: Comparison operators · 2026-09-29
- PHP manual: Type declarations · 2026-09-29
- PHP manual: empty · 2026-09-29
- PHP manual: array_key_exists · 2026-09-29
- PHP manual: Arrays · 2026-09-29
- PHP manual: PDO prepared statements · 2026-09-29
- PHP manual: Transactions and auto-commit · 2026-09-29
- PHP manual: htmlspecialchars · 2026-09-29
- PHP manual: password_hash · 2026-09-29
- PHP manual: password_verify · 2026-09-29
- PHP manual: password_needs_rehash · 2026-09-29
- PHP manual: Securing session settings · 2026-09-29
- PHP manual: session_regenerate_id · 2026-09-29
- PHP manual: Filter constants · 2026-09-29
- OWASP: Authorization · 2026-09-29
- OWASP: CSRF prevention · 2026-09-29
- OWASP: Error handling · 2026-09-29
- Transactional outbox pattern · 2026-09-29
- PHP supported versions · 2026-09-29
- PHP manual: json_decode · 2026-10-01
- PHP manual: json_encode · 2026-10-01
- PHP manual: array_is_list · 2026-10-01
- PHP manual: json_validate · 2026-10-01
- PHP manual: JSON constants · 2026-10-01
- PHP manual: Exceptions · 2026-10-01
- PHP manual: Throwable · 2026-10-01
- PHP manual: fgetcsv · 2026-10-01
- PHP manual: fopen · 2026-10-01
- PHP manual: fgets · 2026-10-01
- PHP manual: fwrite · 2026-10-01
- PHP manual: Generators overview · 2026-10-01
- PHP manual: Generator syntax · 2026-10-01
- PHP manual: iterator_to_array · 2026-10-01
- PHP RFC: Generators · 2026-10-01
What you will explore
0 / 8Explicit types and comparisons
Avoid unexpected decisions when comparing external data.
Intentional arrays and functions
Organize data and separate responsibilities.
Data with parameters
Keep SQL instructions separate from input values.
Security at the web boundary
Handle passwords, HTML output, and errors carefully.
PDO transactions and partial failures
Group related changes and check transaction boundaries.
HTTP, sessions, and per-resource authorization
Protect actions and objects, not only the sign-in page.
JSON, contracts, and explicit failures
Separate syntax, shape, and endpoint rules; retain identity and make failures observable.
Streams, CSV, and controlled imports
Read records progressively, validate the file contract, and track failures during consumption and writing.