【问题标题】:error mysql query in a php code [duplicate]php代码中的错误mysql查询[重复]
【发布时间】:2014-05-04 17:32:57
【问题描述】:

这是我编写的用于编辑数组“文章”中的一行的 php 代码,每一行都由以下内容组成:

(Colonne:     Type)            
(ref     : int(11),
nom   :varchar(25),
cat :  varchar(25),
prix     : int(11),
fabricant : varchar(35),
photo     :varchar(35))

所以我制作了这个 php 代码:

      <?php
require_once("connection.php");
$ref=$_POST['ref'];
$req="Select * from article where ('ref =". $ref."')";
$rs= mysql_query($req) or die(mysql_error());
$AR=mysql_fetch_assoc($rs);

?>
    <html>
    <head>
        <meta charset="utf-8">
    </head>
    <body>
    <form method="POST" action="modifierArticle.php" enctype="multipart/form-data">
        <table>
            <tr>
                <td>Référence:</td>
                <td><input type="text" name="ref" value="<?php echo ($AR['ref']) ?>" readonly="true"></td>
            </tr>
            <tr>
                <td>Nom:</td>
                <td><input type="text" name="nom" value="<?php echo ($AR['nom']) ?>"></td>
            </tr>
            <tr>
                <td> Catégorie:  </td>
                <td><input type="text" name="cat" value="<?php echo ($AR['cat']) ?>"></td>
            </tr>
            <tr>
                <td> Prix Unitaire:  </td>
                <td><input type="text" name="prix" value="<?php echo ($AR['prix']) ?>"></td>
            </tr>
            <tr>
                <td> Fabricant:  </td>
                <td><input type="text" name="fab" value="<?php echo ($AR['fabricant']) ?>"></td>
            </tr>
            <tr>
                <td>Photo: </td>
                <td><input type="file" name="photo"><img src="./images/<?php echo ($AR['photo']) ?>"</td>
            </tr>
            <tr>
                <td></td>
                <td> <input type="submit" value="Enregistrer"></td>
            </tr>
        </table>

    </form>
    </body>
    </html>
<?php
mysql_free_result($rs);
mysql_close($conn);

?>


so i got an error:

注意:未定义的索引:ref in ...\editerArticle.php 第 3 行

注意:未定义索引:ref in ...\editerArticle.php 第 3 行

【问题讨论】:

  • 停止使用 Mysql_* 函数,它们自 PHP 5.5 起已被弃用,因为它们容易受到 SQL 注入的攻击。转到 PDO 或 MYSQLI

标签: php mysql database web


【解决方案1】:

使用此代码

<?php
require_once("connection.php");
$ref=$_POST['ref'];
$req="Select * from article where ref =$ref";
$rs= mysql_query($req) or die(mysql_error());

?>
    <html>
    <had>
        <meta charset="utf-8">
    </had>
    <body>
    <form method="POST" action="modifierArticle.php" enctype="multipart/form-data">
        <table>
            <?php while($AR=mysql_fetch_assoc($rs)) { ?>
            <tr>
                <td>Référence:</td>
                <td><input type="text" name="ref" value="<?php echo ($AR['ref']) ?>" readonly="true"></td>
            </tr>
            <tr>
                <td>Nom:</td>
                <td><input type="text" name="nom" value="<?php echo ($AR['nom']) ?>"></td>
            </tr>
            <tr>
                <td> Catégorie:  </td>
                <td><input type="text" name="cat" value="<?php echo ($AR['cat']) ?>"></td>
            </tr>
            <tr>
                <td> Prix Unitaire:  </td>
                <td><input type="text" name="prix" value="<?php echo ($AR['prix']) ?>"></td>
            </tr>
            <tr>
                <td> Fabricant:  </td>
                <td><input type="text" name="fab" value="<?php echo ($AR['fabricant']) ?>"></td>
            </tr>
            <tr>
                <td>Photo: </td>
                <td><input type="file" name="photo"><img src="./images/<?php echo ($AR['photo']) ?>"</td>
            </tr>
            <tr>
                <td></td>
                <td> <input type="submit" value="Enregistrer"></td>
            </tr>
            <?php } ?>
        </table>

    </form>
    </body>
    </html>
<?php
mysql_free_result($rs);
mysql_close($conn);

?>

【讨论】:

  • 你没有正确启动 while { }
  • 使用 ctrl + f 查找 while
  • ref 是 int 你已经把它放在单引号中,使它成为一个字符串
  • @Tabby 哦,是的,对不起,我的回复很糟糕。我没有注意到。我会编辑它。
【解决方案2】:

你需要使用 isset 和 iempty 来确保你的 $_POST 有价值

<?php
require_once("connection.php");
if (isset($_POST['ref']) && !empty ($_POST['ref']))
{

$ref=$_POST['ref'];
$req="Select * from article where ref ='.$ref.'";
$rs= mysql_query($req) or die(mysql_error());
while($rs = mysql_fetch_array($rs)){

$ref = $rs['ref'];
$nom = $rs['nom'];
$cat = $rs['cat'];
$prix = $rs['prix'];
$fabricant = $rs['fabricant'];
$photo = $rs['photo'];
}
?>

html

<form method="POST" action="modifierArticle.php" enctype="multipart/form-data">
        <table>
            <tr>
                <td>Référence:</td>
                <td><input type="text" name="ref" value="<?php echo $ref; ?>" readonly="true"></td>
            </tr>
            <tr>
                <td>Nom:</td>
                <td><input type="text" name="nom" value="<?php echo $nom; ?>"></td>
            </tr>
            <tr>
                <td> Catégorie:  </td>
                <td><input type="text" name="cat" value="<?php echo $cat; ?>"></td>
            </tr>
            <tr>
                <td> Prix Unitaire:  </td>
                <td><input type="text" name="prix" value="<?php echo $prix; ?>"></td>
            </tr>
            <tr>
                <td> Fabricant:  </td>
                <td><input type="text" name="fab" value="<?php echo $fabricant; ?>"></td>
            </tr>
            <tr>
                <td>Photo: </td>
                <td><input type="file" name="photo"><img src="./images/<?php echo $photo; ?>"</td>
            </tr>
            <tr>
                <td></td>
                <td> <input type="submit" value="Enregistrer"></td>
            </tr>
        </table>

    </form>
    </body>
    </html>

结束mysql连接

<?php
    mysql_free_result($rs);
    mysql_close($conn);

    ?>

编辑 编辑了几个语法错误:)

【讨论】:

  • $cat 中有语法错误
【解决方案3】:
if(isset($_POST['ref']))
{
    $ref=$_POST['ref'];
    $req="Select * from article where ref = $ref";
    $rs= mysql_query($req) or die(mysql_error());
    $AR=mysql_fetch_assoc($rs);
}

$req 中有语法错误,添加 if 条件以确保在运行查询之前 $_POST['ref'] isset

HTML

<html>
    <had>
        <meta charset="utf-8">
    </had>
    <body>
    <form method="POST" action="modifierArticle.php" enctype="multipart/form-data">
        <table>
            <tr>
                <td>Référence:</td>
                <td><input type="text" name="ref" value="<?php echo $AR['ref']; ?>" readonly="true"></td>
            </tr>
            <tr>
                <td>Nom:</td>
                <td><input type="text" name="nom" value="<?php echo $AR['nom']; ?>"></td>
            </tr>
            <tr>
                <td> Catégorie:  </td>
                <td><input type="text" name="cat" value="<?php echo ;AR['cat']; ?>"></td>
            </tr>
            <tr>
                <td> Prix Unitaire:  </td>
                <td><input type="text" name="prix" value="<?php echo $AR['prix']; ?>"></td>
            </tr>
            <tr>
                <td> Fabricant:  </td>
                <td><input type="text" name="fab" value="<?php echo $AR['fabricant']; ?>"></td>
            </tr>
            <tr>
                <td>Photo: </td>
                <td><input type="file" name="photo"><img src="../images/<?php echo $AR['photo']; ?>"</td>
            </tr>
            <tr>
                <td></td>
                <td> <input type="submit" value="Enregistrer"></td>
            </tr>
        </table>

    </form>
    </body>
    </html>

【讨论】:

  • 为什么使用!empty()?这样ref 不能是任何 falsey 值
  • @kingkero 用户刚刚在输入字段中输入数据然后将其删除的东西,在此过程中ref 可能会被设置,但它会为空以避免这种情况我使用!empty()
  • 如果 ref 是 "0",empty() 将返回 true 并且您的逻辑失败 - 所以用户无法搜索 0?
  • @kingkero 你是对的,我的错。现在逻辑对了吗?
  • 是的。同时isSet() 和empty() 也没有意义,因为empty() 将首先检查变量是否已设置;)所以它通常是一个非此即彼的选择
【解决方案4】:

使用 array_key_exists 检查。像这样:

if(array_key_exists('ref', $_POST)) {
 //your code here
}

【讨论】:

    【解决方案5】:

    检查POST请求是否为空

    if(!empty($_POST['ref']))
    {
    $ref=$_POST['ref'];
    }
    else
    {
    echo 'no value';
    exit;
    }
    

    【讨论】:

    • 你好,选民需要理由兄弟/
    猜你喜欢
    • 2016-04-02
    • 2016-08-06
    • 2016-11-22
    • 2018-03-02
    • 1970-01-01
    • 2010-09-05
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多