PHP开发CRUD数据网格时的表单重复提交问题咨询
Hey there! I see you're hitting the classic form resubmission issue when refreshing your PHP CRUD page—totally a common gotcha when you're starting out with PHP, especially coming from C#/Java where post-redirect patterns are often handled under the hood. Let's break down why this is happening and how to fix it step by step.
Why the Duplicate Insert Happens
Right now, your form uses method="GET" to submit data. When you submit the form, the browser adds the form data to the URL (you can see it in the address bar). When you refresh the page, the browser re-sends that exact same GET request—including the form parameters—so your process.php runs the INSERT query again.
On top of that, using GET for actions that modify database data (like inserts/updates/deletes) goes against HTTP best practices—GET should only be used for retrieving data, not changing it.
The Fix: Post/Redirect/Get (PRG) Pattern
The standard solution here is to use the PRG pattern:
- Submit the form via
POSTinstead ofGET - After processing the database insert, redirect the user back to your home page
- Add basic security to prevent SQL injection (since your current code is vulnerable)
Step 1: Update the Form in home.php
Change the form method to POST, and replace the value attributes with placeholder (so users don't have to delete default text every time):
<form action="process.php" method="POST"> <div class="form-group"> <label>Name</label> <input type="text" name="name" class="form-control" placeholder="Enter your name"> </div> <div class="form-group"> <label>Location</label> <input type="text" name="location" class="form-control" placeholder="Enter Your Location"> </div> <div class="form-group"> <button type="submit" name="save" class="btn btn-primary">Save</button> </div> </form>
Step 2: Rewrite process.php with PRG and Security
Modify your processing script to handle POST requests, use prepared statements (to block SQL injection), and redirect after success:
<?php $mysqli = new mysqli('localhost','root','','crud') or die(mysqli_error($mysqli)); if(isset($_POST['save'])) { // Use prepared statements to prevent SQL injection $stmt = $mysqli->prepare("INSERT INTO data (name, location) VALUES (?, ?)"); $stmt->bind_param("ss", $name, $location); // "ss" = two string parameters $name = $_POST['name']; $location = $_POST['location']; if($stmt->execute()) { // Redirect back to home.php after successful insert header("Location: home.php"); exit(); // Always exit after a redirect to stop further code execution } else { die("Error inserting data: " . $mysqli->error); } } ?>
Why This Works
- POST Method: Submits data in the request body (not the URL), so refreshing won't re-send the form data automatically.
- Redirect: After inserting the data, we send a
Locationheader to send the user back tohome.php. Now when they refresh, they're just reloading the home page (a GET request) instead of re-submitting the form. - Prepared Statements: Protects your database from SQL injection attacks—critical for any real-world application, even a learning project!
Bonus: Small Fix in home.php
You had a minor error in your database connection line—mysql_error is for the old MySQL extension, but you're using MySQLi. Update it to:
<?php $mysqli = new mysqli('localhost','root','','crud') or die($mysqli->error); $result= $mysqli->query("SELECT * FROM data")or die($mysqli->error); ?>
That's it! With these changes, refreshing the page won't duplicate your database entries anymore, and your code will be more secure and follow best practices.
内容的提问来源于stack exchange,提问作者Agrito Kryiss

