【发布时间】:2018-10-31 08:22:15
【问题描述】:
请帮助我改进我的代码。我有这个 html 表单来选择一个 .csv 文件扩展名,然后将它上传到我的 sql 数据库中。我该如何改进呢?如果没有选择文件,比如使按钮不可点击。
<form class="ui input" enctype="multipart/form-data" method = "POST" role = "form">
<input type = "file" name ="file" id="file" size = "150">
<button class="ui small red button" type = "submit" class = "btn btn-default" name ="submit" value = "submit">Upload CSV</button>
</form>
然后这是我上传 csv 的 php 代码,我怎样才能弹出消息说“您的文件正在上传,请稍候”和“上传完成”。我的问题是我的csv文件的标题也被上传了如何排除我的csv的第一行?
<?php
if(isset($_POST['submit'])) {
$host = 'localhost';
$user = 'root';
$password = '';
$db = 'jeremy_db';
$con = mysqli_connect($host,$user,$password) or die('Could not' .mysqli_error($con));
mysqli_select_db($con, $db) or die ('Could not' .mysqli_error($con));
$file = $_FILES['file']['tmp_name'];
$handle = fopen($file, "r");
$c = 0;
while(($csvdata = fgetcsv($handle,1000,","))!== FALSE){
$sha1 = $csvdata[0];
$vsdt = $csvdata[1];
$trendx = $csvdata[2];
$sql = "INSERT INTO jeremy_table_trend (sha1,vsdt,trendx) VALUES ('$sha1','$vsdt','$trendx')";
$query = mysqli_query($con , $sql);
$c = $c+1;
}
if($query){
echo "SABRE";
}
else {
echo "SLAM";
}
}
?>
我正在使用php 7,有什么建议吗?
【问题讨论】:
-
您可以从使用准备好的语句开始 - 您对 SQL 注入 atm 持开放态度