You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP赛事结果编辑提交后所有记录内容一致问题求助

问题分析与解决方案

问题根源

  1. 表单元素命名冲突:所有选手的输入框使用相同的name属性(如firstName、lastName),提交表单后$_POST仅会保留最后一个输入框的值,无法区分不同选手的修改内容。
  2. 更新语句无过滤条件:执行UPDATE时未添加WHERE id = ...,导致表中所有记录被统一替换为最后一条表单的内容。
  3. SQL注入漏洞:直接将用户输入拼接进SQL语句,存在严重的安全风险。

修复步骤

1. 修改前端表单

将输入框的name改为数组格式,绑定对应记录的ID,让后端能准确识别每条记录的修改值:

<form method="post" action="">
    <table>
        <th>First Name</th>
        <th>Surname</th>
        <th>Coach</th>
        <th>100 Free</th>
        <th>100 Back</th>
        <th>100 Breast</th>
        <th>100 Fly</th>
        <?php
            while($resultRow = mysqli_fetch_assoc($qResult))
            {
        ?>
        <tr>
            <td><input type="text" value="<?php echo htmlspecialchars($resultRow['first_name']); ?>" name="firstName[<?php echo $resultRow['id']; ?>]"></td>
            <td><input type="text" value="<?php echo htmlspecialchars($resultRow['last_name']); ?>" name="lastName[<?php echo $resultRow['id']; ?>]"></td>
            <td><input type="text" value="<?php echo htmlspecialchars($resultRow['coach']); ?>" name="coach[<?php echo $resultRow['id']; ?>]"></td>
            <td><input type="text" value="<?php echo htmlspecialchars($resultRow['free']); ?>" name="free[<?php echo $resultRow['id']; ?>]"></td>
            <td><input type="text" value="<?php echo htmlspecialchars($resultRow['back']); ?>" name="back[<?php echo $resultRow['id']; ?>]"></td>
            <td><input type="text" value="<?php echo htmlspecialchars($resultRow['breast']); ?>" name="breast[<?php echo $resultRow['id']; ?>]"></td>
            <td><input type="text" value="<?php echo htmlspecialchars($resultRow['fly']); ?>" name="fly[<?php echo $resultRow['id']; ?>]"></td>
        </tr>
        <?php 
            }
        ?>
    </table>
    <button type="submit" name="editResults">Edit Results</button>
</form>
  • 用name="字段名[记录ID]"的格式绑定每条记录,同时用htmlspecialchars()转义输出,防止XSS攻击。

2. 修改后端更新逻辑

使用预处理语句批量更新每条记录,确保仅修改对应ID的内容,同时杜绝SQL注入:

if(isset($_POST["editResults"])){
    // 初始化预处理语句
    $stmt = $conn->prepare("UPDATE results SET first_name = ?, last_name = ?, coach = ?, free = ?, back = ?, breast = ?, fly = ? WHERE id = ?");
    
    // 绑定参数(s表示字符串,i表示整数,根据你的字段类型调整)
    $stmt->bind_param("sssssssi", $firstname, $lastname, $coach, $free, $back, $breast, $fly, $id);
    
    // 遍历所有提交的记录ID
    foreach($_POST['firstName'] as $id => $value){
        $firstname = $_POST['firstName'][$id];
        $lastname = $_POST['lastName'][$id];
        $coach = $_POST['coach'][$id];
        $free = $_POST['free'][$id];
        $back = $_POST['back'][$id];
        $breast = $_POST['breast'][$id];
        $fly = $_POST['fly'][$id];
        
        // 执行更新
        $stmt->execute();
    }
    
    $stmt->close();
    echo "<script> alert('Updated Successful'); </script>";
    header("Location: results.php");
    exit; // 确保后续代码不执行
}
  • 预处理语句通过?占位符替代直接拼接,绑定参数后执行,彻底避免SQL注入。
  • 遍历$_POST['firstName']的键(即记录ID),逐个更新对应记录。

3. 额外优化建议

  • 权限验证部分添加空值判断:如果$row不存在(比如用户ID无效),也应跳转至登录页:
$result = mysqli_query($conn, "SELECT * FROM users WHERE id = '$id'");
$row = mysqli_fetch_assoc($result);
if(!$row || $row['rank'] != 4){
    echo '<script>alert("You are not authorized to access this!");location="index.php";</script>';
    exit;
}
  • 数据库连接后添加错误判断:
if(!$conn){
    die("Connection failed: " . mysqli_connect_error());
}

内容的提问来源于stack exchange,提问作者Elux

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 09:38:08