You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android登录后添加车位提交表单出现Undefined Array Key错误求助

问题排查:添加车位时出现「Undefined Array Key」错误

问题描述

用户通过邮箱密码登录Android应用后,填写车位信息并点击提交按钮,触发「Warning: Undefined Array Key」错误。

核心原因分析

  1. Android端参数提交逻辑漏洞:代码中对email和password添加了非空判断,仅当值不为null时才会将参数提交到后端。如果登录状态传递的这两个值为空(或Intent未正确传递),后端将无法获取到这两个参数。
  2. PHP后端参数处理不严谨:直接通过$_POST['email']和$_POST['password']获取参数,未做存在性检查,当参数缺失时就会触发「Undefined Array Key」警告。
  3. SQL注入风险:原PHP代码直接将用户输入拼接到SQL语句中,存在严重的安全隐患。

解决方案

1. 修复Android端参数提交逻辑

确保email和password参数始终被提交,即使为空也传递空字符串(登录状态下这两个值应有效存在,兜底处理避免后端报错):

@Override
protected Map<String, String> getParams() throws AuthFailureError {
    Map<String, String> params = new HashMap<>();
    params.put("ps_title", title);
    params.put("ps_address", address);
    params.put("postcode", postcode);
    params.put("cost_per_hour", cost);
    params.put("is_available", isAvailable ? "Available" : "Not Available");
    // 直接提交参数,无需条件判断,兜底处理空值
    params.put("email", email != null ? email : "");
    params.put("password", password != null ? password : "");
    return params;
}

2. 修复PHP后端参数处理与安全问题

对所有POST参数做存在性检查,添加必填项验证,同时改用预处理语句彻底解决SQL注入风险:

<?php
// 定义数据库连接参数
$servername = "localhost";
$username = "root";
$password = "";
$dbname = "mydb";

// 创建数据库连接
$conn = new mysqli($servername, $username, $password, $dbname);

// 检查连接错误
if ($conn->connect_error) {
    die("连接失败: " . $conn->connect_error);
}

// 安全获取POST参数,默认值为空字符串
$ps_title = isset($_POST['ps_title']) ? trim($_POST['ps_title']) : '';
$ps_address = isset($_POST['ps_address']) ? trim($_POST['ps_address']) : '';
$postcode = isset($_POST['postcode']) ? trim($_POST['postcode']) : '';
$cost_per_hour = isset($_POST['cost_per_hour']) ? trim($_POST['cost_per_hour']) : '';
$is_available = isset($_POST['is_available']) ? $_POST['is_available'] : "Not Available";
$email = isset($_POST['email']) ? trim($_POST['email']) : '';
$password = isset($_POST['password']) ? trim($_POST['password']) : '';

// 提前验证必填参数是否完整
if (empty($ps_title) || empty($ps_address) || empty($postcode) || empty($cost_per_hour) || empty($email) || empty($password)) {
    echo "必填参数缺失";
    $conn->close();
    exit;
}

// 检查邮政编码是否存在(预处理语句防注入)
$postcode_id = null;
$stmt = $conn->prepare("SELECT PostcodeID FROM postcode WHERE Postcode = ?");
$stmt->bind_param("s", $postcode);
$stmt->execute();
$result = $stmt->get_result();
if ($result->num_rows > 0) {
    $row = $result->fetch_assoc();
    $postcode_id = $row['PostcodeID'];
} else {
    // 插入新邮政编码
    $stmt = $conn->prepare("INSERT INTO postcode (Postcode) VALUES (?)");
    $stmt->bind_param("s", $postcode);
    $stmt->execute();
    $postcode_id = $stmt->insert_id;

    // 获取地理信息(对编码进行URL转义)
    $encoded_postcode = urlencode($postcode);
    $geocode_url = "https://maps.googleapis.com/maps/api/geocode/json?address=$encoded_postcode&key=AIzaSyB0wJammsFsGqsX5X0s97U10oj_s5_jgM8";
    $geocode_data = json_decode(file_get_contents($geocode_url));
    if ($geocode_data && $geocode_data->status == "OK") {
        $latitude = $geocode_data->results[0]->geometry->location->lat;
        $longitude = $geocode_data->results[0]->geometry->location->lng;
        $stmt = $conn->prepare("UPDATE postcode SET Latitude = ?, Longitude = ? WHERE PostcodeID = ?");
        $stmt->bind_param("ddi", $latitude, $longitude, $postcode_id);
        $stmt->execute();
    }
}
$stmt->close();

// 通过邮箱密码获取H_ID(预处理语句防注入)
$h_id = null;
$stmt = $conn->prepare("SELECT H_ID FROM households WHERE H_Email = ? AND H_Password = ?");
$stmt->bind_param("ss", $email, $password);
$stmt->execute();
$result = $stmt->get_result();
if ($result->num_rows > 0) {
    $row = $result->fetch_assoc();
    $h_id = $row['H_ID'];

    // 插入车位信息(预处理语句防注入)
    $stmt = $conn->prepare("INSERT INTO parkingspace (PS_Title, PS_Address, PostcodeID, H_ID, PS_Cost, PS_Status) VALUES (?, ?, ?, ?, ?, ?)");
    $stmt->bind_param("ssids", $ps_title, $ps_address, $postcode_id, $h_id, $cost_per_hour, $is_available);
    if ($stmt->execute()) {
        echo "车位添加成功!";
    } else {
        echo "添加失败: " . $stmt->error;
    }
} else {
    echo "邮箱或密码无效。";
}
$stmt->close();

// 关闭数据库连接
$conn->close();
?>

关键修复点说明

  • Android端:确保核心参数始终提交,避免后端因参数缺失触发警告。
  • PHP端:
    • 用isset()检查所有POST参数,避免Undefined Array Key警告。
    • 增加必填参数验证,提前拦截无效请求。
    • 全部改用预处理语句,彻底消除SQL注入风险。
    • 对邮政编码做URL编码,避免地理信息请求因特殊字符失败。

内容的提问来源于stack exchange,提问作者Hasini Thilakarathna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 21:42:35