gpt4 book ai didi

带有变量的 PHP ORDER BY

转载 作者:行者123 更新时间:2023-11-29 05:24:36 25 4
gpt4 key购买 nike

我是 php 的初学者,在使用变量更改 ORDER BY 时遇到了一些问题。我试图研究并弄清楚,但没有运气。我希望表单名称“filter”将选项名称传递给 php 变量“filter”,然后按 mysql 选择查询中的“filter”变量排序。我在这里缺少什么?

代码如下:

根据建议,我已经编辑了代码并发布了编辑内容。

    <center><h2> Saved Weapons List</h2>

<form name="filter" action="" method="post">
<select name="filter">
<option value="weaponType"> Weapon Type</option>
<option value="weaponCategory"> Weapon Category</option>
</select>
<input type="submit">
</form>
</center>

<?php
$con=mysqli_connect("localhost","username","pass","db_name");
// Check connection
if (mysqli_connect_errno())
{
echo "Failed to connect to MySQL: " . mysqli_connect_error();
}

$filter = $_POST['filter'];

$result = mysqli_query($con,"SELECT * FROM weapons ORDER BY '{$filter}' desc");



while($row = mysqli_fetch_array($result))
{
$row['masterwork'] = ( intval( $row['masterwork']) == 1) ? "Yes" : "No";
echo "<center>";
echo "<table border='1' class='display'>";
echo "<tr>";
echo "<td>Weapon Name: </td>";
echo "<td>" . $row['weaponName'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Creator: </td>";
echo "<td>" . $row['creator'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Weapon Category: </td>";
echo "<td>" . $row['weaponCategory'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Weapon Sub-Category: </td>";
echo "<td>" . $row['weaponSubCategory'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Cost: </td>";
echo "<td>" . $row['costAmount'] . " " . $row['costType'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Damage(S): </td>";
echo "<td>" . $row['damageS'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Damage(M): </td>";
echo "<td>" . $row['damageM'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Critical: </td>";
echo "<td>" . $row['critical'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Range Increment: </td>";
echo "<td>" . $row['rangeIncrement'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Weight: </td>";
echo "<td>" . $row['weight'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Weapon Type: </td>";
echo "<td>" . $row['weaponType'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Masterwork: </td>";
echo "<td>" . $row['masterwork'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Attributes: </td>";
echo "<td>" . $row['attributes'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Special Abilities: </td>";
echo "<td>" . $row['specialAbilities'] . "</td>";
echo "</tr>";
echo "<tr>";
echo "<td>Additional Info: </td>";
echo "<td>" . $row['additionalInfo'] . "</td>";
echo "</tr>";
}
echo "</table>";
echo "</center>";

mysqli_close($con);
?>

最佳答案

多次更新(主要是出于安全原因。正如@Wrikken 在评论中所写 - 您的代码要求进行注入(inject))。

首先。将选项值更改为某些内容(可能是数字),然后在 PHP 中检查它。

    <option value="filter1"> Weapon Type</option>
<option value="filter2"> Weapon Category</option>

然后用PHP过滤

$filter = 'weaponType';

switch($_POST["filter"]) {
case 'filter2': $filter = 'weaponCategory'; break;
}

其次。如果设置了 $filter - 运行查询...

if (isset($filter)) {
$result = mysqli_query($con,"SELECT * FROM weapons ORDER BY " . $filter . " desc");
while($row = mysqli_fetch_array($result))
{
/* output */
}
}

关于带有变量的 PHP ORDER BY,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/21739391/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com