【问题标题】:Error when using php ajax to check input data with the system使用php ajax与系统检查输入数据时出错
【发布时间】:2021-12-31 07:36:06
【问题描述】:

我正在学习如何使用 ajax 来检查系统中是否已经存在注册的电子邮件数据。但是在使用时,success:function(data)返回的结果始终是原始php页面的源代码(如下图所示)。 这是我的javascript代码

    $(document).ready(function(){
    $("#email").change(function(){
        $.ajax({
            URL: "process-email.php",
            type: "post",
            data: {email:$(this).val()},
            success:function(res) {
                console.log(res);
            }
        })
    })
})

这是数据处理的目的地

<?php
    include "config/config.php";
    $result = mysqli_query($conn,"SELECT * FROM tb_user WHERE email='" . $_POST['email'] . "'");
    if(mysqli_num_rows($result) <= 0)
    {
        echo "OK.";
    }else{
        echo "Already exist.";
    }
?>

这是发送到我的主站点的数据

有什么办法可以解决吗?谢谢大家!

【问题讨论】:

  • 您的代码很容易受到SQL Injection 攻击,因为在 sql 中直接使用了用户提供的原始数据。为了帮助减轻这种威胁,您应该始终使用Prepared Statements。一个非常有用的指南,有大量的示例代码是PHP Delusions
  • 是的,但我只是想看看 ajax 是如何工作的。我仍在努力解决这个错误
  • 您是否将 ajax 请求发送到同一页面?
  • 我已经把ajax请求移到了同一个页面,我仔细看了。但是还是报错
  • 如果发送 ajax 的 javascript 与处理 HTTP 请求的 PHP 在同一页面内,那么您需要在发送输出之前刷新缓冲区,否则响应将包含该页面中的所有 HTML似乎正在发生的事情

标签: javascript php ajax


【解决方案1】:

我仍然不清楚 AJAX 请求是否被发送到同一页面,但无论如何以下可能会有所帮助,因为它确实解决了几个问题 - 即 sql 注入的可能性,缓冲区的刷新以确保仅发送正确制作的响应,并且除非有有效的电子邮件,否则不会发送任何请求。

<?php

    if( $_SERVER['REQUEST_METHOD']=='POST' && isset( $_POST['email'] ) ){
    
        # flush any previous content
        ob_clean();
        
        include "config/config.php";
        
        /*
            Create a Prepared Statement
            Bind the placeholder to the POSTed email & execute.
            Obtain the number of rows returned & close statement.
        */
        $sql='SELECT * FROM tb_user WHERE email=?';
        $stmt=$conn->prepare( $sql );
        $stmt->bind_param('s',$_POST['email']);
        $stmt->execute();       
        $stmt->store_result();
        
        $rows=$stmt->num_rows;
        
        $stmt->free_result();
        $stmt->close();
        
        
        # terminate with response message
        exit( $rows == 0 ? 'OK.' : 'Already exists.' );

    }
?>

Email validation function

const validateEmail=( email )=>{
  return String( email )
    .toLowerCase()
    .match(
      /^(([^<>()[\]\\.,;:\s@"]+(\.[^<>()[\]\\.,;:\s@"]+)*)|(".+"))@((\[[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\])|(([a-zA-Z\-0-9]+\.)+[a-zA-Z]{2,}))$/
    );
};



$(document).ready(function(){
    $("#email").change(function(){
        let email=$(this).val();
        if( validateEmail( email ) ){
            /*
                No point sending the ajax request 
                unless the email is valid.
            */
            $.ajax({
                URL: "process-email.php",
                type: "post",
                data:{ 'email':email },
                success:function(res) {
                    console.log(res);
                }
            })
        }
    })
})

【讨论】:

    猜你喜欢
    • 2012-12-13
    • 1970-01-01
    • 1970-01-01
    • 2021-04-28
    • 2018-12-11
    • 1970-01-01
    • 2015-01-30
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多