You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将用户ID从check_username传递到get_entries以过滤数据库数据?

解决方案

1. 先修复SQL注入漏洞(必须处理)

原代码直接拼接用户名、密码到SQL语句里,会触发严重的SQL注入风险,先把数据库操作改成参数化查询:

# database_handler.py
def check_username(username, password):
    # 参数化查询,避免SQL注入
    sql = "SELECT * FROM parent WHERE username = %s AND password = %s"
    cursor.execute(sql, (username, password))
    result = cursor.fetchone()
    return result

def get_entries(parent_id):
    # 同样用参数化查询处理用户ID
    sql = """
        SELECT * FROM entrymonitoring 
        WHERE student_id = (SELECT mystudent FROM parent_mystudent WHERE parent = %s) 
        ORDER BY `date` DESC LIMIT 6
    """
    cursor.execute(sql, (parent_id,))
    results = cursor.fetchall()
    return results

2. 登录后存储用户ID

登录成功后,把用户ID存到Kivy App的全局属性里,方便其他页面调用:

# LoginScreen.py
from kivy.app import App

class LoginScreen(MDScreen):
    def login(self):
        username = self.ids.username.text
        password = self.ids.password.text

        login_check = database_handler.check_username(username, password)

        if login_check:
            # 假设parent表的第一个字段是用户ID,根据你的数据库结构调整索引
            App.get_running_app().current_parent_id = login_check[0]
            Snackbar(text="Login successful").open()
            # 这里可以添加跳转到PublicScreen的代码,比如:
            # self.manager.current = 'public_screen'
        else:
            Snackbar(text="invalid username/password").open()

3. 在消息页面传递用户ID

加载消息时,从全局属性取出用户ID,传给get_entries函数:

# PublicScreen.py
from kivy.app import App

class PublicScreen(MDScreen):
    def load_posts(self):
        self.ids.posts.clear_widgets()
        
        # 获取当前登录用户的ID
        parent_id = App.get_running_app().current_parent_id
        if not parent_id:
            Snackbar(text="Please login first").open()
            return
        
        entry = database_handler.get_entries(parent_id)

        # 以下卡片创建代码保持不变
        for msg in entry:
            msg_card = MDCard(
                orientation="vertical",
                padding="20dp",
                size_hint=[None, None],
                size=["500dp", "120dp"],
                pos_hint={"center_x": .5, "center_y": .5}
            )

            msg_title = MDLabel(
                halign="left",
                text="AMSAI",
                theme_text_color="Secondary",
                size_hint_y=None,
                height="40dp"
            )

            title_separator = MDSeparator(
                height="1dp"
            )

            msg_body = MDLabel(
                halign="left",
                text="Your student exited the school grounds at " + str(msg[2]),
            )

            msg_timestamp = MDLabel(
                text=str(msg[3]),
                halign="right",
                theme_text_color="Secondary",
                size_hint_y=None,
                height="5dp"
            )

            msg_card.add_widget(msg_title)
            msg_card.add_widget(title_separator)
            msg_card.add_widget(msg_body)
            msg_card.add_widget(msg_timestamp)

            self.ids.posts.add_widget(msg_card)

注意事项

  • 确认parent表中用户ID的索引位置,如果ID不是第一个字段,把login_check[0]改成对应索引(比如login_check[1])。
  • 除了用App实例存储ID,也可以用全局变量或自定义会话类,但App实例是Kivy项目中最常用的全局数据存储方式。

内容的提问来源于stack exchange,提问作者zheni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 18:17:43