why all the sql use $db->bindVars , can not put vars directly in sql string?