You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

表单提交后Sweet Alert提示框不显示问题求助

问题排查:SweetAlert无法显示PHP变量值

数据已成功插入数据库,但SweetAlert弹窗中的$Name和$state变量无法正常显示,普通alert()函数可正常输出变量值。

错误代码示例

<?php
session_start();
error_reporting(0);
include('config.php');
if(isset($_POST['create']))
{
$Name=$_POST['Name'];
$state=$_POST['state'];

$sql="INSERT INTO  tblstudent(Name,state) VALUES('$Name','$state')";
$query = $dbh->prepare($sql);
echo $sql;
echo $Name;
echo $state;
$query->execute();
$lastInsertId = $dbh->lastInsertId();
if($lastInsertId)
{
    echo '
    <script>
        $(document).ready(function(){
            swal({
                title: "Successfully save! ${$Name}/${$state} ",
                html: "Your request for ${$Name}/${$state}  has been successfully filled",
                timer: 5000,
                timerProgressBar: true,
            }).then(function() {
                window.location = "index.php";
            });
        });
    
</script>
';
 
}
else 
{
$_SESSION['error']="Something went wrong. Please try again";
header('location:manage-region2.php');
}

}
?>
<!DOCTYPE html>
<html >
<head>
<head>
<script src="https://cdnjs.cloudflare.com/ajax/libs/sweetalert/2.1.2/sweetalert.min.js"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.2.1/jquery.min.js"></script>
</head>  
</head>
<body>
<div class="panel-body">
<form role="form" method="post">
<div class="form-group">
<label>Name</label>
<input class="form-control" type="text" name="Name" autocomplete="off" required />
</div>
<div class="form-group">
<label>State Name</label>
<input class="form-control" type="text" name="state" autocomplete="off" required />
</div>
<button type="submit" name="create" class="btn btn-info">Create </button>
</form>
</div>
</body>
</html>

问题原因及修复方案

1. 核心问题:PHP变量解析错误

你在单引号包裹的JavaScript字符串里用${$Name}的写法完全错误:

  • PHP单引号字符串内的变量不会被解析,会原样输出${$Name}文本
  • 即便改用双引号,${$Name}也不是正确的变量输出格式,直接写$Name即可

2. 修复后的代码片段

推荐使用以下两种方式之一修改SweetAlert输出代码,同时注意对用户输入做安全转义:

方式一:字符串拼接模式

if($lastInsertId)
{
    // 转义变量,避免XSS攻击和JS语法错误
    $safeName = htmlspecialchars($Name, ENT_QUOTES);
    $safeState = htmlspecialchars($state, ENT_QUOTES);
    
    echo '
    <script>
        $(document).ready(function(){
            swal({
                title: "Successfully save! ' . $safeName . '/' . $safeState . ' ",
                html: "Your request for ' . $safeName . '/' . $safeState . ' has been successfully filled",
                timer: 5000,
                timerProgressBar: true,
            }).then(function() {
                window.location = "index.php";
            });
        });
    </script>
    ';
}

方式二:双引号包裹模式

if($lastInsertId)
{
    $safeName = htmlspecialchars($Name, ENT_QUOTES);
    $safeState = htmlspecialchars($state, ENT_QUOTES);
    
    echo "
    <script>
        $(document).ready(function(){
            swal({
                title: \"Successfully save! $safeName/$safeState \",
                html: \"Your request for $safeName/$safeState has been successfully filled\",
                timer: 5000,
                timerProgressBar: true,
            }).then(function() {
                window.location = \"index.php\";
            });
        });
    </script>
    ";
}

3. 额外安全提示

你的SQL语句存在SQL注入风险,建议改用参数化查询:

// 安全的参数化写法
$sql = "INSERT INTO tblstudent(Name, state) VALUES(:name, :state)";
$query = $dbh->prepare($sql);
$query->bindParam(':name', $Name);
$query->bindParam(':state', $state);
$query->execute();

内容的提问来源于stack exchange,提问作者gorakh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 11:17:06