【问题标题】:How do I get the value of the form into a MySQL table? [duplicate]如何将表单的值放入 M​​ySQL 表中? [复制]
【发布时间】:2021-02-13 23:46:11
【问题描述】:

我想要的只是将var1 从输入中获取到我的 SQL 表中。它总是会创建一个新的 ID,所以这是可行的,但它会在 Email 行中留下一个空白字段。我以前从未使用过 SQL,在这里也找不到类似的东西。我以为问题也可能出在表的设置上,但在那里找不到任何问题。

<input name="var1" id="contact-email2" class="contact-input abo-email" type="text" placeholder="Email *" required="required"/>
<form class="newsletter-form" action="newsletter.php" method="POST">
             <button class="contact-submit" id="abo-button" type="submit" value="Abonnieren">Absenden
             </button>
</form>
<?php

$user = "user";
$password = "password";
$host = "localhost:0000";
$dbase = "base";
$table = "table";

// Connection to DBase
$con = new mysqli($host, $user, $password, $dbase) or die("Can't connect");
$var1 = $_POST['var1'];

$sql = "INSERT INTO table (id, Email) VALUES ('?', '_POST[var1]')";

$result = mysqli_query($con, $sql) or die("Not working");

echo 'You are in!' . '<br>';

mysqli_close($con);

【问题讨论】:

  • 请阅读stackoverflow.com/questions/60174/…并使用带参数的准备好的语句
  • 您的表单真的是这样的吗?您的输入在您的表单之外。
  • @Dharman 是的,据我所知,把它放在里面并没有真正改变任何东西。
  • @noah222 它必须在里面,否则该值将不会发送到服务器。您检查过实际发送的内容吗?你知道浏览器检查器吗?
  • 如果这只是一个错字,那么你可以删除这个问题。

标签: php html mysql forms


【解决方案1】:

简单回答

这里有一些问题;但简单的答案是:

 $sql = "INSERT INTO table (id, Email) VALUES ('?', '_POST[var1]')";

...应该是:

 $sql  = "INSERT INTO {$table} (id, Email) VALUES ('?', '{$var1}')";

...OR 假设 id 设置为自动递增等。

$sql  = "INSERT INTO {$table} (Email) VALUES ('{$var1}')";

更多涉及的答案

您真的应该花时间将prepared 语句与具有用户输入的SQL 一起使用。在query 中使用它们之前,您至少应该自己escape 字符串。

mysqli

$user     = "user";  
$password = "password";  
$host     = "localhost:0000";  
$dbase    = "base";  
$table    = "table";  

$mysqli = new mysqli($host, $user, $password, $dbase); // Make connection to DB

if($mysqli->connect_error) {
    die("Error: Could not connect to database.");
}

$email  = $_POST["var1"];                              // User input from form

$sql    = "INSERT INTO {$table} (Email) VALUES(?)";    // SQL query using ? as a place holder for our value
$query  = $mysqli->prepare($sql);                      // Prepare the statement
$query->bind_param("s", $email);                       // Bind $email {s = data type string} to the ? in the SQL
$query->execute();                                     // Execute the query

PDO

$user     = "user";  
$password = "password";  
$host     = "localhost:0000";  
$dbase    = "base";  
$table    = "table";



try {
  $pdo = new pdo( "mysql:host={$host};dbname={$dbase}", $user, $password); // Make connection to DB
}
catch(PDOexception $e){
  die("Error: Could not connect to database.");
}

$email  = $_POST["var1"];                           // User input from form

$sql    = "INSERT INTO {$table} (Email) VALUES(?)"; // SQL query using ? as a place holder for our value
$query  = $pdo->prepare($sql);                      // Prepare the statement
$query->execute([$email]);                          // Execute the query binding `(array)0=>$email` to place holder in SQL

【讨论】:

  • @noah222 是的,错误报告。 mysqli 和 PDO 都有错误报告,这个答案没有显示如何启用。
  • 你能回滚你上次的编辑吗? new PDO 周围不应该有任何 try-catch 并且你不应该手动检查连接错误。 Should we ever check for mysqli_connect() errors manually?
【解决方案2】:

id 是唯一的 id 吗?这是自动递增的?? 如果是这样,您应该这样做

    <?php

    $user = "user";  
    $password = "password";  
    $host = "localhost:0000";  
    $dbase = "base";  
    $table = "table";  

    $mysqli = new mysqli($host,$user,$password,$dbase);
    $email = $_POST['var1'];

    // you might want to make sure the string is safe this is escaping any special characters

    $statment = $mysqli->prepare("INSERT INTO table (Email) VALUES (?)");
    $statment->bind_param("s", $email);

    if(isset($_POST['var1'])) {
            $statment->execute();
    }

    $mysqli->close();
    $statment->close();

【讨论】:

  • 感谢您的回答!我可能仍然有问题,因为我收到了一个致命错误:未捕获的错误:在 null 上调用成员函数 real_escape_string()(第 8 行)。 Id 是主键并自动递增!
  • 把你的代码发给我,我帮你看看,随时欢迎帮助。
猜你喜欢
  • 1970-01-01
  • 2013-02-10
  • 2021-02-11
  • 2021-10-05
  • 1970-01-01
  • 1970-01-01
  • 2016-03-11
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多