gpt4 book ai didi

php - 尝试使用 php 将数据从表单存储到数据库中

转载 作者:行者123 更新时间:2023-11-29 19:48:11 25 4
gpt4 key购买 nike

嘿,提前致谢,我正在尝试从表单中获取数据并将其输入数据库。我正在遵循有关如何执行此操作的指南,但该指南没有说明任何不起作用的情况......

我刚刚开始使用 PHP,所以我的技能非常有限,但是我确实理解我编写的所有代码,但它不起作用! php 脚本不会越过下面的 if 语句,我不明白为什么:

// Check for existing user with the new id
$sql = "SELECT COUNT(*) FROM sessions.users WHERE userid = '$_POST[newid]'";
$result = mysqli_query($cxn, $sql);
if (!$result) {
error('A database error occurred in processing your '.
'submission.\nIf this error persists, please '.
'contact you@example.com. This is from error 1');

整个代码:

注册.php

<?php //signup.php
include 'common.php';
include 'db.php';

if(!isset($_POST['submitok'])):
// display user signup form

?>


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">

<head>
<title>New User Registration</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
</head>
<body>
<h3>New User Registration Form</h3>
<p><font color="orangered" size="+1"><tt><b>*</b></tt></font> indicates a required field</p>
<form method="post" action="<?=$_SERVER['PHP_SELF']?>">
<table border="0" cellpadding="0" cellspacing="5">
<tr>
<td align="right">
<p>User ID</p>
</td>
<td>
<input name="newid" type="text" maxlength="100" size="25" />
<font color="orangered" size="+1"><tt><b>*</b></tt></font>
</td>
</tr>
<tr>
<td align="right">
<p>Full Name</p>
</td>
<td>
<input name="newname" type="text" maxlength="100" size="25" />
<font color="orangered" size="+1"><tt><b>*</b></tt></font>
</td>
</tr>
<tr>
<td align="right">
<p>E-Mail Address</p>
</td>
<td>
<input name="newemail" type="text" maxlength="100" size="25" />
<font color="orangered" size="+1"><tt><b>*</b></tt></font>
</td>
</tr>
<tr valign="top">
<td align="right">
<p>Other Notes</p>
</td>
<td>
<textarea wrap="soft" name="newnotes" rows="5" cols="30"></textarea>
</td>
</tr>
<tr>
<td align="right" colspan="2">
<hr noshade="noshade" />
<input type="reset" value="Reset Form" />
<input type="submit" name="submitok" value=" OK " />
</td>
</tr>
</table>
</form>
</body>
</html>
<?php
else:
//process sign up submission
dbConnect('sessions');

if ($_POST['newid']=='' or $_POST['newname']==''
or $_POST['newemail']=='') {
error('One or more required fields were left blank.\\n'.
'Please fill them in and try again.');
}

// Check for existing user with the new id
$sql = "SELECT COUNT(*) FROM sessions.users WHERE userid = '$_POST[newid]'";
$result = mysqli_query($cxn, $sql);
if (!$result) {
error('A database error occurred in processing your '.
'submission.\nIf this error persists, please '.
'contact you@example.com. This is from error 1');
}

if (@mysqli_result($result,0,0)>0) {
error('A user already exists with your chosen userid.\n'.
'Please try another.');
}

$newpass = substr(md5(time()),0,6);

$sql = "INSERT INTO sessions.users SET
userid = '$_POST[newid]',
password = PASSWORD('$newpass'),
fullname = '$_POST[newname]',
email = '$_POST[newemail]',
notes = '$_POST[newnotes]'";
if (!mysqli_query($sql))
error('A database error occurred in processing your '.
'submission.\nIf this error persists, please '.
'contact you@example.com. This is from error 2');

// Email the new password to the person.
$message = "G'Day!

Your personal account for the Project Web Site
has been created! To log in, proceed to the
following address:

http://www.example.com/

Your personal login ID and password are as
follows:

userid: $_POST[newid]
password: $newpass

You aren't stuck with this password! Your can
change it at any time after you have logged in.

If you have any problems, feel free to contact me at
<you@example.com>.

-Your Name
Your Site Webmaster
";

mail($_POST['newemail'],"Your Password for the Project Website",
$message, "From:Your Name <you@example.com>");
?>

<!DOCTYPE html PUBLIC "-//W3C/DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title> Registration Complete </title>
<meta http-equiv="Content-Type"
content="text/html; charset=iso-8859-1" />
</head>
<body>
<p><strong>User registration successful!</strong></p>
<p>Your userid and password have been emailed to
<strong><?=$_POST['newemail']?></strong>, the email address
you just provided in your registration form. To log in,
click <a href="index.php">here</a> to return to the login
page, and enter your new personal userid and password.</p>
</body>
</html>
<?php
endif;
?>

db.php

<?php // db.php

$dbhost = 'localhost';
$dbuser = 'root';
$dbpass = '';

function dbConnect($db='') {
global $dbhost, $dbuser, $dbpass;

$cxn = mysqli_connect($dbhost,$dbuser,$dbpass);

mysqli_select_db($cxn,$db)
or die ("Couldn’t select database.");


return $cxn;
}
?>

common.php

<?php // common.php

function error($msg) {
?>
<html>
<head>
<script language="JavaScript">
<!--
alert("<?=$msg?>");
history.back();
//-->
</script>
</head>
<body>
</body>
</html>
<?php
exit;
}
?>

任何关于为什么这个 if 语句总是产生错误的帮助都会很大 - 谢谢。

最佳答案

您没有在可用范围内分配数据库连接。您dbConnect()函数返回它,只是没有对返回值执行任何操作。

dbConnect('sessions'); 应为 $cxn = dbConnect('sessions');

如果您使用mysqli_error(),您将会收到关于问题原因的提醒。让 MySQL 告诉你它不喜欢什么。

最后,您应该在查询中使用绑定(bind)参数,而不是直接注入(inject)用户提供的数据。搜索“mysqli 绑定(bind)参数”之类的内容来了解​​如何执行此操作。你现在拥有的东西很容易受到攻击。

对于您的 INSERT 语句,请使用绑定(bind)参数:

$sql = "INSERT INTO sessions.users (userid, password, fullname, email, notes) VALUES (?, ?, ?, ?, ?)";

$stmt = mysqli_prepare($sql);
mysqli_stmt_bind_param($stmt, 'issss', $newID, PASSWORD($newpass), $fullName, $email, $notes);

if(!mysqli_stmt_execute($stmt))
{
// use this for debugging, but do NOT leave it in production code
die(mysqli_error($cxn));
}

mysqli_stmt_close($stmt);

以上未经测试,因此您可能需要进行一些小的调整。它至少应该让您很好地了解该做什么。

此外,请确保 PASSWORD()确实是您想要使用的。我有一种感觉,但我不想假设。

关于php - 尝试使用 php 将数据从表单存储到数据库中,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/40892569/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com