提交表单遇HTTP ERROR 405错误,求排查解决(附代码)
HTTP ERROR 405(Method Not Allowed)问题排查与解决
问题背景
使用POST方法访问http://127.0.0.1:5501/Assignment%202%20-%20Web%20development/submit.php时,页面及控制台均返回「This page isn’t working. HTTP ERROR 405」,请求返回状态码为405 Method Not Allowed。
提交的代码
index.html
<!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>XYZ Workshop Registration</title> <link rel="stylesheet" href="styles.css"> </head> <body> <div class="container"> <h1>XYZ Workshop Registration</h1> <form id="registration-form" method="POST" action="submit.php"> <div class="form-group"> <label for="fullname">Full Name:</label> <input type="text" id="fullname" name="fullname" required> </div> <div class="form-group"> <label for="email">Email:</label> <input type="email" id="email" name="email" required> </div> <div class="form-group"> <label for="phone">Phone:</label> <input type="tel" id="phone" name="phone" pattern="[0-9]{10}" required> </div> <button type="submit">Register</button> </form> </div> <script src="script.js"></script> </body> </html>
submit.php
<?php // Check if the form is submitted via POST method if ($_SERVER["REQUEST_METHOD"] == "POST") { // Check if all required fields are set if(isset($_POST['fullname']) && isset($_POST['email']) && isset($_POST['phone'])) { // Collect form data $fullname = $_POST['fullname']; $email = $_POST['email']; $phone = $_POST['phone']; // Perform validation (you can add more validation if needed) // Connect to your database (replace with your database credentials) $servername = "localhost"; $username = "your_username"; $password = "your_password"; $dbname = "your_database_name"; // Create connection $conn = new mysqli($servername, $username, $password, $dbname); // Check connection if ($conn->connect_error) { die("Connection failed: " . $conn->connect_error); } // Prepare SQL statement to insert data into the database (replace with your table name and column names) $sql = "INSERT INTO participants (fullname, email, phone) VALUES ('$fullname', '$email', '$phone')"; // Execute SQL statement if ($conn->query($sql) === TRUE) { echo "New record created successfully"; } else { echo "Error: " . $sql . "<br>" . $conn->error; } // Close database connection $conn->close(); } else { echo "All fields are required"; } } // Check if GET request is made if ($_SERVER["REQUEST_METHOD"] == "GET") { // Perform actions based on parameters passed in the URL // For example, you can retrieve data from the database and return it if(isset($_GET['id'])) { // Fetch data based on the ID passed in the URL $id = $_GET['id']; // Connect to the database and retrieve data // Replace this with your own logic to fetch data $servername = "localhost"; $username = "your_username"; $password = "your_password"; $dbname = "your_database_name"; // Create connection $conn = new mysqli($servername, $username, $password, $dbname); // Check connection if ($conn->connect_error) { die("Connection failed: " . $conn->connect_error); } // Prepare SQL statement to fetch data from the database $sql = "SELECT * FROM participants WHERE id = $id"; // Execute SQL statement $result = $conn->query($sql); // Check if data is retrieved if ($result->num_rows > 0) { // Output data of each row while($row = $result->fetch_assoc()) { echo "Full Name: " . $row["fullname"]. " - Email: " . $row["email"]. " - Phone: " . $row["phone"]. "<br>"; } } else { echo "No results found"; } // Close database connection $conn->close(); } else { echo "ID parameter is required"; } } ?>
问题根源
你当前使用的是**Live Server(端口5501)**这类静态文件服务器,它仅能处理HTML、CSS、JS等静态资源,无法解析执行PHP代码。当表单提交POST请求到PHP文件时,静态服务器无法识别该请求类型,直接返回405 Method Not Allowed错误。
此外,你的PHP代码存在SQL注入风险,这是后续需要优化的安全问题。
解决步骤
1. 切换至支持PHP的服务器环境
必须使用可解析PHP的服务器,推荐两种方案:
- 本地集成环境:安装XAMPP/WAMP/LAMP,将项目文件放入服务器根目录(如XAMPP的
htdocs文件夹),通过http://localhost/[项目文件夹]/index.html访问页面。 - PHP内置服务器:在项目目录打开终端,执行命令:
随后通过php -S localhost:8000http://localhost:8000/index.html访问页面,提交表单时会正确解析submit.php。
2. 修正数据库配置
代码中数据库连接信息为占位符,需替换为实际凭据:
$servername = "localhost"; // 默认无需修改 $username = "root"; // XAMPP默认用户名为root $password = ""; // XAMPP默认密码为空 $dbname = "workshop_db"; // 你创建的数据库名称
同时需确保已在MySQL中创建participants表,表结构包含id(自增主键)、fullname、email、phone字段。
3. 修复SQL注入漏洞
当前代码直接将用户输入拼接到SQL语句中,存在严重安全风险,建议改用预处理语句:
插入数据部分修改:
// 替换原INSERT相关代码 $stmt = $conn->prepare("INSERT INTO participants (fullname, email, phone) VALUES (?, ?, ?)"); $stmt->bind_param("sss", $fullname, $email, $phone); // s代表字符串类型 if ($stmt->execute()) { echo "New record created successfully"; } else { echo "Error: " . $stmt->error; } $stmt->close();
查询数据部分修改:
// 替换原SELECT相关代码 $stmt = $conn->prepare("SELECT * FROM participants WHERE id = ?"); $stmt->bind_param("i", $id); // i代表整数类型 $stmt->execute(); $result = $stmt->get_result(); // 后续结果处理逻辑不变 $stmt->close();
内容的提问来源于stack exchange,提问作者Devanshi Patel
相关产品推荐
相关产品推荐

