PHP赛事结果编辑提交后所有记录内容一致问题求助
问题分析与解决方案
问题根源
- 表单元素命名冲突:所有选手的输入框使用相同的
name属性(如firstName、lastName),提交表单后$_POST仅会保留最后一个输入框的值,无法区分不同选手的修改内容。 - 更新语句无过滤条件:执行
UPDATE时未添加WHERE id = ...,导致表中所有记录被统一替换为最后一条表单的内容。 - SQL注入漏洞:直接将用户输入拼接进SQL语句,存在严重的安全风险。
修复步骤
1. 修改前端表单
将输入框的name改为数组格式,绑定对应记录的ID,让后端能准确识别每条记录的修改值:
<form method="post" action=""> <table> <th>First Name</th> <th>Surname</th> <th>Coach</th> <th>100 Free</th> <th>100 Back</th> <th>100 Breast</th> <th>100 Fly</th> <?php while($resultRow = mysqli_fetch_assoc($qResult)) { ?> <tr> <td><input type="text" value="<?php echo htmlspecialchars($resultRow['first_name']); ?>" name="firstName[<?php echo $resultRow['id']; ?>]"></td> <td><input type="text" value="<?php echo htmlspecialchars($resultRow['last_name']); ?>" name="lastName[<?php echo $resultRow['id']; ?>]"></td> <td><input type="text" value="<?php echo htmlspecialchars($resultRow['coach']); ?>" name="coach[<?php echo $resultRow['id']; ?>]"></td> <td><input type="text" value="<?php echo htmlspecialchars($resultRow['free']); ?>" name="free[<?php echo $resultRow['id']; ?>]"></td> <td><input type="text" value="<?php echo htmlspecialchars($resultRow['back']); ?>" name="back[<?php echo $resultRow['id']; ?>]"></td> <td><input type="text" value="<?php echo htmlspecialchars($resultRow['breast']); ?>" name="breast[<?php echo $resultRow['id']; ?>]"></td> <td><input type="text" value="<?php echo htmlspecialchars($resultRow['fly']); ?>" name="fly[<?php echo $resultRow['id']; ?>]"></td> </tr> <?php } ?> </table> <button type="submit" name="editResults">Edit Results</button> </form>
- 用
name="字段名[记录ID]"的格式绑定每条记录,同时用htmlspecialchars()转义输出,防止XSS攻击。
2. 修改后端更新逻辑
使用预处理语句批量更新每条记录,确保仅修改对应ID的内容,同时杜绝SQL注入:
if(isset($_POST["editResults"])){ // 初始化预处理语句 $stmt = $conn->prepare("UPDATE results SET first_name = ?, last_name = ?, coach = ?, free = ?, back = ?, breast = ?, fly = ? WHERE id = ?"); // 绑定参数(s表示字符串,i表示整数,根据你的字段类型调整) $stmt->bind_param("sssssssi", $firstname, $lastname, $coach, $free, $back, $breast, $fly, $id); // 遍历所有提交的记录ID foreach($_POST['firstName'] as $id => $value){ $firstname = $_POST['firstName'][$id]; $lastname = $_POST['lastName'][$id]; $coach = $_POST['coach'][$id]; $free = $_POST['free'][$id]; $back = $_POST['back'][$id]; $breast = $_POST['breast'][$id]; $fly = $_POST['fly'][$id]; // 执行更新 $stmt->execute(); } $stmt->close(); echo "<script> alert('Updated Successful'); </script>"; header("Location: results.php"); exit; // 确保后续代码不执行 }
- 预处理语句通过
?占位符替代直接拼接,绑定参数后执行,彻底避免SQL注入。 - 遍历
$_POST['firstName']的键(即记录ID),逐个更新对应记录。
3. 额外优化建议
- 权限验证部分添加空值判断:如果
$row不存在(比如用户ID无效),也应跳转至登录页:
$result = mysqli_query($conn, "SELECT * FROM users WHERE id = '$id'"); $row = mysqli_fetch_assoc($result); if(!$row || $row['rank'] != 4){ echo '<script>alert("You are not authorized to access this!");location="index.php";</script>'; exit; }
- 数据库连接后添加错误判断:
if(!$conn){ die("Connection failed: " . mysqli_connect_error()); }
内容的提问来源于stack exchange,提问作者Elux
相关产品推荐
相关产品推荐

