【发布时间】:2014-04-17 20:47:06
【问题描述】:
我想通过使用 php 复选框将 "0" 或 "1" 插入 mysql 数据库。但是,它无法修改或插入 mysql 数据库。
我的编码edit.php:
<?php
switch($_GET['action']) {
case "Modify":
/*************************** case "modify" **********************/
$colname_RsStaff = "1";
if (isset($_GET['staffid'])) {
$colname_RsStaff = (get_magic_quotes_gpc())
? $_GET['staffid'] : addslashes($_GET['staffid']);
}
mysql_select_db($database_conn, $conn);
$query_RsStaff = "SELECT * FROM `tbl_staff`
WHERE `tbl_staff`.`staffid` = '".$_GET['staffid']."'";
$RsStaff = mysql_query($query_RsStaff, $conn) or die(mysql_error());
$row_RsStaff = mysql_fetch_assoc($RsStaff);
$totalRows_RsStaff = mysql_num_rows($RsStaff);
$subagent = $row_RsStaff['subagent'];
$subum = $row_RsStaff['subum'];
$subssm = $row_RsStaff['subssm'];
$subtutor = $row_RsStaff['subtutor'];
break;
/* ****************Add**************** */
default:
$subagent = "";
$subum = "";
$subssm = "";
$subtutor = "";
break;
}
?>
<form name="staff" method="post" onsubmit="return validateForm()" action="commit.php?action=<?php echo $_GET['action'] ?>">
<tr>
<td height="12" align="right" bgcolor="#CCCCCC"><h5> </h5></td>
<td height="12" align="left" bgcolor="#dfdfdf"> <input type="checkbox" name="subagent[]" value="<?php echo $subagent; ?>" /> Agent <input type="checkbox" name="subum[]" value="<?php echo $subum; ?>" /> UM </td>
<td rowspan="2" align="left" bgcolor="#dfdfdf">
<h6> * Selected one or more</h6></td>
</tr>
<tr>
<td height="12" align="right" bgcolor="#CCCCCC"><h5> </h5></td>
<td height="12" align="left" bgcolor="#dfdfdf"> <input type="checkbox" name="subssm[]" value="<?php echo $subssm; ?>" /> SSM <input type="checkbox" name="subtutor[]" value="<?php echo $subtutor; ?>" /> Tutor </td>
</tr>
<input type="submit" name="Submit" value="<?php echo $_GET['action'] ?>" />
发帖到commit.php
$editFormAction = $_SERVER['PHP_SELF'];
if (isset($_SERVER['QUERY_STRING'])) {
$editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
}
switch ($_GET['action']) {
case "Create":
$staffid = $_POST['staffid'];
mysql_select_db($database_conn, $conn);
$result ="SELECT * FROM tbl_staff WHERE staffid = '".$_POST['staffid']."'";
$Staff = mysql_query($result, $conn) or die(mysql_error());
$totalRows_Staff = mysql_num_rows($Staff);
$insertSQL = sprintf("INSERT INTO tbl_staff (subagent, subum, subssm, subtutor) VALUES (%s, %s, %s, %s)",
GetSQLValueString($_POST['subagent'], "text"),
GetSQLValueString($_POST['subum'], "text"),
GetSQLValueString($_POST['subssm'], "text"),
GetSQLValueString($_POST['subtutor'], "text"),
mysql_select_db($database_conn, $conn);
$Result1 = mysql_query($insertSQL, $conn) or die(mysql_error());
}
$insertGoTo = "tr_staff.php";
if (isset($_SERVER['QUERY_STRING'])) {
$insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
$insertGoTo .= $_SERVER['QUERY_STRING'];
}
header(sprintf("Location: %s", $insertGoTo));
}
break;
/************************* update *************************/
case "Modify":
$updateSQL = sprintf("UPDATE tbl_staff SET subagent=%s, subum=%s, subssm=%s, subtutor=%s WHERE staffid=%s",
GetSQLValueString($_POST['subagent'], "text"),
GetSQLValueString($_POST['subum'], "text"),
GetSQLValueString($_POST['subssm'], "text"),
GetSQLValueString($_POST['subtutor'], "text"),
GetSQLValueString($_POST['staffid'], "int"));
mysql_select_db($database_conn, $conn);
$Result1 = mysql_query($updateSQL, $conn) or die(mysql_error());
$insertGoTo = "tr_staff.php";
if (isset($_SERVER['QUERY_STRING'])) {
$insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
$insertGoTo .= $_SERVER['QUERY_STRING'];
}
header(sprintf("Location: %s", $insertGoTo));
//}
break;
}
?>
任何建议将不胜感激。
【问题讨论】:
-
表单正在发布,您正在寻找 $_GET 变量。
-
停止使用mysql也不错,开始使用msqli或pdo..
-
请避免使用mysql防止SQL注入..