【问题标题】:Add variable number of fields to a database table with PHP使用 PHP 向数据库表中添加可变数量的字段
【发布时间】:2012-07-18 10:54:27
【问题描述】:

我似乎想不出一个正确的方法来向数据库表中添加可变数量的字段。假设我正在构建一个 Web 应用程序,访问者可以在其中注册和管理他们的联系人。他们可以通过表单添加个人联系人,该表单具有以下文本输入字段:

  • 联系人姓名
  • 电话号码
  • 电子邮件地址
  • 公司
  • 地址
  • 首页

在此表单中,只需要“联系人姓名”字段,因此完全可以在不知道联系人电话号码的情况下添加联系人的电子邮件地址。如何在 PHP 中正确实现?

他们以前做过的方式涉及遍历 $_POST 数组并检查每个特定字段是否已提交。如果已提交字段,则其字段名称将添加到 SQL 语句中。然后我们对值做同样的事情。

我的直觉告诉我,这种工作方式是非常错误的,但我想不出任何其他方式来做到这一点......

function generateSQLStatement($_POST) {

    // Add field names to SQL statement
    foreach ($_POST as $field => $value) {
        if (!empty($value)) {
            $sql .= $field . ', ';
        }
    }

    // Remove last comma and space
    $sql = substr($sql, 0, -2);

    // Add values to SQL statement
    $sql .= ') VALUES (';
    foreach ($_POST as $field => $value) {
        if (!empty($value)) {
            $sql .= $value . ', ';
        }
    }

    // Remove last comma and space
    $sql = substr($sql, 0, -2);

    $sql .= ')';

    return $sql;
}

【问题讨论】:

  • 查看active record patterns。我曾经按照您现在的方式进行操作,但是将每个表的列建模为对象类使其更容易处理。错误也更少。
  • 我真的希望你正在清理那些发布的值......
  • 目前的方法没有什么特别的问题。我不会依赖数据库字段名称的帖子名称,我会有一个数组,但仍然循环查看它们是否被填写是好的。它实际上不是可变数量的字段,字段是固定的,只是有些是空的(很正常的东西)。提交空的不会伤害
  • 输入值总是得到验证然后被清理,但我没有在我的代码中包含这些步骤,因为它与问题本身无关。仍然感谢您指出应始终验证用户输入(并可能进行清理)。

标签: php forms


【解决方案1】:

请注意,在下面的代码中,SANITIZE_MEmysqli::real_escape_string 等方法的占位符,或者任何适合您情况的方法。您需要根据需要调整此答案。

function generateSQLStatement($_POST) {

    $fieldNames = "";
    $values = "";

    foreach ($_POST as $field => $value) {
        if (!empty($value)) {
            if (!empty($fieldNames)) {
                $fieldNames .= ',';
                $values .= ',';
            }
            $fieldNames .= SANITIZE_ME($field);
            $values .= "'" . SANITIZE_ME($value) . "'";

        }
    }

    return "($fieldNames) VALUES ($values)";
}

这种方法只使用一个循环,因此速度更快。但您可能希望根据预定义的可接受字段数组验证您的字段名称,以防有人编辑发布到您的脚本的表单并输入无效的字段名称。

编辑

可以使用更通用的方法来创建一个实用函数,您可以轻松地在整个应用程序中与其他表一起重用该函数:

这很多可以放在一些通用的包含文件中:

// An array whose keys are valid table names and
// whose values are arrays of valid field names
// within the table named in the key
$acceptableFields = array(
    'contacts' => array(
        // valid fields in the 'contacts' table
        'name', 'address' //...
    )
    // ... other mappings, if desired
);

function isValidField($table, $field) {
    if (!isset($acceptableFields[$table]))
        return false;

    return in_array($field, $acceptableFields[$table]); 
    // Note that in_array is case-sensitive, so you may want 
    // to just manually loop through $acceptableFields[$table]
    // and compare strings yourself.
}

function insertData($table, array $fieldValuesMap, mysqli $mysqli) {
    // First, some self-explanatory validation:
    if ($table === null)
        throw new InvalidArgumentException('$table cannot be null');

    if (!is_string($table))
        throw new InvalidArgumentException('$table must be a String');

    if (empty($table))
        throw new InvalidArgumentException('$table cannot be an empty String');

    if (!isset($acceptableFields[$table]))
        throw new InvalidArgumentException("\"$table\" is an invalid table name");

    $fieldNames = "";
    $values = "";

    foreach ($fieldValuesMap as $field => $value) {
        // check the field name is valid for the given table
        // and that the value is not empty.  You may want to
        // add a logging mechanism for invalid field names to
        // help track bugs or even malicious use
        if (isValidField($table, $field) && !empty($value)) {
            // check to see whether there are any items in 
            // the lists already
            if (!empty($fieldNames)) {
                // yes, so add commas:
                $fieldNames .= ',';
                $values .= ',';
            }

            // no need to escape the field name as we have already
            // checked that it is valid
            $fieldNames .= $field;
            // but we do need to escape the value
            $values .= "'" . $mysqli->real_escape_string($value) . "'";

        }
    }

    // check whether we've actually got anything to insert:
    if (empty($fieldNames))
        return NULL;

    return $mysqli->query("INSERT INTO $table ($fieldNames) VALUES ($values)");
}

在页面上添加联系人的示例用法:

require_once "above.file"; // whatever it's called

if ($_POST) {

    $mysqli = new MySQLi(/*...*/);
    if (mysqli_connect_errno()) {
        // handle connection error
    } else {
        // set your charset
        $mysqli->set_charset("utf8"); // or whatever you use

        $result = insertData('contacts', $_POST, $mysqli);

        if ($result === NULL) {
            // There was nothing to insert
        } elseif ($result === FALSE) {
            // An error occurred, handle it here
        } else {
            // Success!  Use $mysqli->insert_id to get your new 
            // record's ID (if appropriate).
        }
    }

}
//
//==============================================

做一些额外的工作,你最终会得到一些灵活且可重复使用的东西。不过,就我个人而言,我更喜欢更面向对象(活动记录)的方法。

【讨论】:

  • 我同意这个答案。您也可以考虑简单地插入空字段的选项。
  • @FranciscoO。是的,我考虑过只插入空字符串,但后来认为 OP 在他的应用程序的其他地方读取这些字段时可能依赖于这些字段中的 NULL 值(或数据库架构中指定的其他默认值)。
  • 我的应用程序确实依赖于 NULL 值,所以空字符串是没有选择的。
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 2016-01-11
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多