PHP中将简历保存至Blob报错,请求排查代码问题
PHP代码问题排查与修复
问题代码
daftar( cucidata( $_POST["username"]), cucidata($_POST["password1"]), cucidata($_POST["password2"]), cucidata($_POST["name"]), cucidata($_POST["email"]), $_FILES["photo"]["name"], $con, $_FILES["photo"]["tmp_name"], cucidata($_POST["dob"]), cucidata($_POST["gender"]), cucidata($_POST["hp"]), cucidata($_POST["address"]), cucidata($_POST["university"]), cucidata($_POST["gd"]), cucidata($_POST["qualitification"]), cucidata($_POST["fos"]), cucidata($_POST["mos"]), cucidata($_POST["ai"]), cucidata($_POST["jt"]), cucidata($_POST["cn"]), cucidata($_POST["pe1"]), cucidata($_POST["pe2"]), ($_FILES["resume"]["name"]), $con, $_FILES["resume"]["tmp_name"] ); //save the resume to blob $resumeFileType = strtolower(pathinfo($resume,PATHINFO_EXTENSION)); //dapatkan jenis resume $resumeData =addslashes(file_get_contents($resumeFileType)); $resumeProperties = getimageSize($resumeFileType); mysqli_query($con,"INSERT INTO tbl_user (username,pwd,name,email,picture,pictype, dob,gender,hp,address,university,gd, qualitification,fos,mos,ai,jt,cn,pe1,pe2, resume,resumetype) values ('$user','$pwd','$name','$email','{$imgData}', '{$imageProperties['mime']}','$dob','$gender', '$hp','$address','$university','$gd', '$qualitification','$fos','$mos','$ai', '$jt','$cn','$pe1','$pe2','{$resumeData}', '{$resumeProperties['mime']})") or die (mysqli_error($con));
报错信息
Warning: file_get_contents(pdf): failed to open stream: No such file or directory in C:\laragon\www\intern\include\main_function.php on line 38
Warning: getimagesize(pdf): failed to open stream: No such file or directory in C:\laragon\www\intern\include\main_function.php on line 39
Notice: Trying to access array offset on value of type bool in C:\laragon\www\intern\include\main_function.php on line 42 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '')' at line 1
问题分析与修复方案
1. 简历文件读取逻辑错误
问题点:
- 变量
$resume未定义,pathinfo返回的是文件扩展名(如pdf)而非实际文件路径 - 用扩展名作为参数传给
file_get_contents和getimagesize,这两个函数需要完整文件路径而非扩展名 getimagesize仅支持图片文件,无法处理PDF,调用后返回false,后续访问$resumeProperties['mime']触发报错
- 变量
修复代码:
// 先验证简历上传是否成功 if ($_FILES["resume"]["error"] !== UPLOAD_ERR_OK) { die("简历上传失败,请重试"); } $resumeTmpPath = $_FILES["resume"]["tmp_name"]; // 读取简历文件内容 $resumeData = addslashes(file_get_contents($resumeTmpPath)); // 用finfo获取正确的MIME类型(支持所有文件格式) $finfo = new finfo(FILEINFO_MIME_TYPE); $resumeMime = $finfo->file($resumeTmpPath);
2. SQL语法与变量问题
问题点:
- SQL语句中
'{$resumeProperties['mime']})'引号闭合错误,导致语法报错 $user、$pwd、$imgData等变量未在当前代码片段中定义,需确保这些变量来自daftar函数的正确传递或赋值- 直接拼接变量到SQL语句存在严重SQL注入风险
- SQL语句中
修复后的SQL示例(使用预处理语句):
// 假设$user、$pwd等变量已正确定义并完成转义处理 $sql = "INSERT INTO tbl_user (username,pwd,name,email,picture,pictype, dob,gender,hp,address,university,gd, qualitification,fos,mos,ai,jt,cn,pe1,pe2, resume,resumetype) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)"; $stmt = mysqli_prepare($con, $sql); mysqli_stmt_bind_param($stmt, "ssssssssssssssssssssss", $user, $pwd, $name, $email, $imgData, $imageProperties['mime'], $dob, $gender, $hp, $address, $university, $gd, $qualitification, $fos, $mos, $ai, $jt, $cn, $pe1, $pe2, $resumeData, $resumeMime ); mysqli_stmt_execute($stmt) or die(mysqli_error($con));
3. 其他注意事项
- 确认
cucidata函数已正确处理用户输入,过滤潜在的XSS和注入风险 - 检查图片上传逻辑是否存在类似错误,统一文件处理逻辑
- 所有变量使用前必须确认已定义赋值,避免未定义变量警告
内容的提问来源于stack exchange,提问作者Fatihah Shuhaimi
相关产品推荐
相关产品推荐

