You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

网页删除超链接功能失效,无法删除数据库行求助

问题:删除数据库行功能失效,无法获取commentId变量

我给表格添加了删除链接,本应通过delete.inc.php删除数据库中对应ID的行,但点击后直接返回test.php,无法获取到commentId变量。试过把$_GET改成$_POST并给链接加method="POST",还是没用。

网页上的表格

删除链接代码

<td><a href="includes/delete.inc.php?commentId=<?php echo $row["commentId"]; ?>">Delete</a></td>

相关文件代码

dbh.inc.php

<?php

$serverName = "localhost";
$dBUsername = "root";
$dBPassword = "";
$dBName = "php-login";


$conn = mysqli_connect($serverName, $dBUsername, $dBPassword, $dBName);


if (!$conn){
    die("connection failed: " . mysqli_connect_error());
}

test.php

<?php
include_once 'header.php';
include "includes/dbh.inc.php";
include 'includes/test.inc.php';
?>


<link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css" integrity="sha384-Gn5384xqQ1aoWXA+058RXPxPg6fy4IWvTNh0E263XmFcJlSAwiGgFAW/dAiS6JXm" crossorigin="anonymous">
</head>
<body>
    <div class="container">
        <div class="box">
            <h4 class="display-4 text-center">Comments</h4><br>
            <?php if (isset($_GET['success'])) { ?>
            <div class="alert alert-success" role="alert">
              <?php echo $_GET['success']; ?>
            </div>
            <?php } ?>
            <table class="table table-striped">
              <thead>
                <tr>
                  <th scope="col">#</th>
                  
                  <th scope="col">Username</th>
                  <th scope="col">Comment</th>
                  <th scope="col">Action</th>
                </tr>
              </thead>
              <?php
                $i=0;
                while($row = mysqli_fetch_array($result)) {
                ?>
                
                <td><?php echo $row["commentId"]; ?></td>
                <td><?php echo $row["usersUid"]; ?></td>
                <td><?php echo $row["comment"]; ?></td>
                <td><a href="includes/delete.inc.php?commentId=<?php echo $row["commentId"]; ?>">Delete</a></td>
                </tr>
                <?php
                $i++;
                }
                ?>
            </table>      
        </div>
    </div>
</body>
</html>

test.inc.php

<?php  

include "dbh.inc.php";

$sql = "SELECT * FROM commenttb ORDER BY commentId DESC";
$result = mysqli_query($conn, $sql);

delete.inc.php

<?php

include "dbh.inc.php";
if(isset($_GET['commentId'])) {
   $id = $_GET['commentId'];
   $delete = "DELETE FROM `commenttb` WHERE `commentId` ='$id'";
   $result = mysqli_query($conn, $delete);
   if ($result) {
      header("Location: ../test.php?success=successfully deleted");
   } else {
      header("Location: ../test.php?error=unknown error occurred");
   }
}else {
   header("Location: ../test.php?error=smth gone wrong");
}

问题排查与解决

  1. 修复HTML结构错误
    看test.php的表格循环代码,你在while循环里直接输出<td>,但漏掉了<tr>的开始标签!浏览器渲染异常可能导致链接生成出错,这大概率是核心问题。修改后代码:

    <?php
    $i=0;
    while($row = mysqli_fetch_array($result)) {
    ?>
    <tr>
       <td><?php echo $row["commentId"]; ?></td>
       <td><?php echo $row["usersUid"]; ?></td>
       <td><?php echo $row["comment"]; ?></td>
       <td><a href="includes/delete.inc.php?commentId=<?php echo $row["commentId"]; ?>">Delete</a></td>
    </tr>
    <?php
    $i++;
    }
    ?>
    
  2. 验证参数传递
    右键点击删除链接,复制链接地址,确认URL里是否包含commentId=xxx(比如includes/delete.inc.php?commentId=5)。如果没有,检查commenttb表是否真的有commentId字段,或者mysqli_fetch_array是否正确获取到数据。

  3. 修复SQL注入漏洞并添加调试
    原代码存在SQL注入风险,同时添加调试信息帮你定位问题,修改delete.inc.php:

    <?php
    include "dbh.inc.php";
    // 开启调试模式(上线后关闭)
    error_reporting(E_ALL);
    ini_set('display_errors', 1);
    
    if(isset($_GET['commentId'])) {
       $id = (int)$_GET['commentId'];
       // 使用预处理语句防注入
       $delete = "DELETE FROM `commenttb` WHERE `commentId` = ?";
       $stmt = mysqli_prepare($conn, $delete);
       mysqli_stmt_bind_param($stmt, "i", $id);
       $result = mysqli_stmt_execute($stmt);
       
       if ($result) {
          echo "删除成功,受影响行数:" . mysqli_affected_rows($conn);
          header("refresh:2; url=../test.php?success=successfully deleted");
       } else {
          echo "SQL错误:" . mysqli_error($conn);
          header("refresh:2; url=../test.php?error=" . urlencode(mysqli_error($conn)));
       }
    }else {
       echo "未获取到commentId参数";
       header("refresh:2; url=../test.php?error=missing commentId");
    }
    ?>
    
  4. 关于POST方法的正确用法
    <a>标签不支持method="POST",如果要改用POST,需要把链接改成表单:

    <td>
       <form action="includes/delete.inc.php" method="POST" style="display:inline;">
          <input type="hidden" name="commentId" value="<?php echo $row["commentId"]; ?>">
          <button type="submit">Delete</button>
       </form>
    </td>
    

    同时把delete.inc.php里的$_GET替换成$_POST。

内容的提问来源于stack exchange,提问作者MaxDex

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 16:15:51