表单提交后Sweet Alert提示框不显示问题求助
问题排查:SweetAlert无法显示PHP变量值
数据已成功插入数据库,但SweetAlert弹窗中的$Name和$state变量无法正常显示,普通alert()函数可正常输出变量值。
错误代码示例
<?php session_start(); error_reporting(0); include('config.php'); if(isset($_POST['create'])) { $Name=$_POST['Name']; $state=$_POST['state']; $sql="INSERT INTO tblstudent(Name,state) VALUES('$Name','$state')"; $query = $dbh->prepare($sql); echo $sql; echo $Name; echo $state; $query->execute(); $lastInsertId = $dbh->lastInsertId(); if($lastInsertId) { echo ' <script> $(document).ready(function(){ swal({ title: "Successfully save! ${$Name}/${$state} ", html: "Your request for ${$Name}/${$state} has been successfully filled", timer: 5000, timerProgressBar: true, }).then(function() { window.location = "index.php"; }); }); </script> '; } else { $_SESSION['error']="Something went wrong. Please try again"; header('location:manage-region2.php'); } } ?> <!DOCTYPE html> <html > <head> <head> <script src="https://cdnjs.cloudflare.com/ajax/libs/sweetalert/2.1.2/sweetalert.min.js"></script> <script src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.2.1/jquery.min.js"></script> </head> </head> <body> <div class="panel-body"> <form role="form" method="post"> <div class="form-group"> <label>Name</label> <input class="form-control" type="text" name="Name" autocomplete="off" required /> </div> <div class="form-group"> <label>State Name</label> <input class="form-control" type="text" name="state" autocomplete="off" required /> </div> <button type="submit" name="create" class="btn btn-info">Create </button> </form> </div> </body> </html>
问题原因及修复方案
1. 核心问题:PHP变量解析错误
你在单引号包裹的JavaScript字符串里用${$Name}的写法完全错误:
- PHP单引号字符串内的变量不会被解析,会原样输出
${$Name}文本 - 即便改用双引号,
${$Name}也不是正确的变量输出格式,直接写$Name即可
2. 修复后的代码片段
推荐使用以下两种方式之一修改SweetAlert输出代码,同时注意对用户输入做安全转义:
方式一:字符串拼接模式
if($lastInsertId) { // 转义变量,避免XSS攻击和JS语法错误 $safeName = htmlspecialchars($Name, ENT_QUOTES); $safeState = htmlspecialchars($state, ENT_QUOTES); echo ' <script> $(document).ready(function(){ swal({ title: "Successfully save! ' . $safeName . '/' . $safeState . ' ", html: "Your request for ' . $safeName . '/' . $safeState . ' has been successfully filled", timer: 5000, timerProgressBar: true, }).then(function() { window.location = "index.php"; }); }); </script> '; }
方式二:双引号包裹模式
if($lastInsertId) { $safeName = htmlspecialchars($Name, ENT_QUOTES); $safeState = htmlspecialchars($state, ENT_QUOTES); echo " <script> $(document).ready(function(){ swal({ title: \"Successfully save! $safeName/$safeState \", html: \"Your request for $safeName/$safeState has been successfully filled\", timer: 5000, timerProgressBar: true, }).then(function() { window.location = \"index.php\"; }); }); </script> "; }
3. 额外安全提示
你的SQL语句存在SQL注入风险,建议改用参数化查询:
// 安全的参数化写法 $sql = "INSERT INTO tblstudent(Name, state) VALUES(:name, :state)"; $query = $dbh->prepare($sql); $query->bindParam(':name', $Name); $query->bindParam(':state', $state); $query->execute();
内容的提问来源于stack exchange,提问作者gorakh
相关产品推荐
相关产品推荐

