You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

点击搜索按钮后无法在现有文本框显示数据库匹配数据的问题求助

Fixing Your Search Function Issue

Hey there! Let's break down why your search isn't displaying the correct results—even when matching data exists in your database, you're seeing "No Record Found" because your AJAX request isn't sending the search value to your PHP script, and we'll also fix a critical security issue while we're at it.

Key Problems in Your Current Code

  • AJAX isn't passing the search parameter: Your JavaScript sends an empty POST request to searchIcPatient.php, so $_POST['icpayer'] is never set in PHP, forcing it to hit the else branch every time.
  • SQL Injection Vulnerability: Directly inserting user input into your SQL query is a huge security risk—attackers could manipulate your database with malicious input.

Step-by-Step Fixes

1. Update Your JavaScript to Send the Search Value

Modify your AJAX call to include the IC number from the input field:

$('#searchValue').on('click', function(){
    // Grab the IC number from the input box
    const icPayer = $('input[name="icpayer"]').val();
    
    $.ajax({
        type : "POST",
        url : 'searchIcPatient.php',
        // Add this data property to send the IC value to PHP
        data: { icpayer: icPayer },
        success : function(data) {
            $('#payername').val(data);
        },
        // Optional: Add an error handler to debug issues easily
        error: function(xhr, status, error) {
            console.log('AJAX Error:', error);
        }
    });
});

2. Secure and Fix Your PHP Script

Use prepared statements to prevent SQL injection, and properly handle cases where no matching records are found:

<?php
// Check if we received a valid IC parameter
if(isset($_POST['icpayer']) && !empty(trim($_POST['icpayer']))){
    $searchValue = trim($_POST['icpayer']);
    
    // Use a prepared statement to avoid SQL injection
    $query = "SELECT patientname FROM ptregistration WHERE patientic = ?";
    $stmt = mysqli_prepare($con, $query);
    // Bind the search value to the query ( "s" = string type )
    mysqli_stmt_bind_param($stmt, "s", $searchValue);
    mysqli_stmt_execute($stmt);
    $result = mysqli_stmt_get_result($stmt);
    
    // Check if we found a matching record
    if($row = mysqli_fetch_assoc($result)){
        echo $row['patientname'];
    } else {
        echo "No Record Found";
    }
    
    // Clean up the statement
    mysqli_stmt_close($stmt);
} else {
    // No valid IC was provided
    echo "No Record Found";
}
?>

Quick Debugging Tip

If you run into issues later, open your browser's developer tools (press F12), go to the Network tab, and click your search button. You can check the AJAX request's payload to confirm the IC number is being sent, and view the response from PHP to see what's being returned.

内容的提问来源于stack exchange,提问作者Hidayah Rosli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 06:59:08