网页删除超链接功能失效,无法删除数据库行求助
问题:删除数据库行功能失效,无法获取commentId变量
我给表格添加了删除链接,本应通过delete.inc.php删除数据库中对应ID的行,但点击后直接返回test.php,无法获取到commentId变量。试过把$_GET改成$_POST并给链接加method="POST",还是没用。

删除链接代码
<td><a href="includes/delete.inc.php?commentId=<?php echo $row["commentId"]; ?>">Delete</a></td>
相关文件代码
dbh.inc.php
<?php $serverName = "localhost"; $dBUsername = "root"; $dBPassword = ""; $dBName = "php-login"; $conn = mysqli_connect($serverName, $dBUsername, $dBPassword, $dBName); if (!$conn){ die("connection failed: " . mysqli_connect_error()); }
test.php
<?php include_once 'header.php'; include "includes/dbh.inc.php"; include 'includes/test.inc.php'; ?> <link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css" integrity="sha384-Gn5384xqQ1aoWXA+058RXPxPg6fy4IWvTNh0E263XmFcJlSAwiGgFAW/dAiS6JXm" crossorigin="anonymous"> </head> <body> <div class="container"> <div class="box"> <h4 class="display-4 text-center">Comments</h4><br> <?php if (isset($_GET['success'])) { ?> <div class="alert alert-success" role="alert"> <?php echo $_GET['success']; ?> </div> <?php } ?> <table class="table table-striped"> <thead> <tr> <th scope="col">#</th> <th scope="col">Username</th> <th scope="col">Comment</th> <th scope="col">Action</th> </tr> </thead> <?php $i=0; while($row = mysqli_fetch_array($result)) { ?> <td><?php echo $row["commentId"]; ?></td> <td><?php echo $row["usersUid"]; ?></td> <td><?php echo $row["comment"]; ?></td> <td><a href="includes/delete.inc.php?commentId=<?php echo $row["commentId"]; ?>">Delete</a></td> </tr> <?php $i++; } ?> </table> </div> </div> </body> </html>
test.inc.php
<?php include "dbh.inc.php"; $sql = "SELECT * FROM commenttb ORDER BY commentId DESC"; $result = mysqli_query($conn, $sql);
delete.inc.php
<?php include "dbh.inc.php"; if(isset($_GET['commentId'])) { $id = $_GET['commentId']; $delete = "DELETE FROM `commenttb` WHERE `commentId` ='$id'"; $result = mysqli_query($conn, $delete); if ($result) { header("Location: ../test.php?success=successfully deleted"); } else { header("Location: ../test.php?error=unknown error occurred"); } }else { header("Location: ../test.php?error=smth gone wrong"); }
问题排查与解决
修复HTML结构错误
看test.php的表格循环代码,你在while循环里直接输出<td>,但漏掉了<tr>的开始标签!浏览器渲染异常可能导致链接生成出错,这大概率是核心问题。修改后代码:<?php $i=0; while($row = mysqli_fetch_array($result)) { ?> <tr> <td><?php echo $row["commentId"]; ?></td> <td><?php echo $row["usersUid"]; ?></td> <td><?php echo $row["comment"]; ?></td> <td><a href="includes/delete.inc.php?commentId=<?php echo $row["commentId"]; ?>">Delete</a></td> </tr> <?php $i++; } ?>验证参数传递
右键点击删除链接,复制链接地址,确认URL里是否包含commentId=xxx(比如includes/delete.inc.php?commentId=5)。如果没有,检查commenttb表是否真的有commentId字段,或者mysqli_fetch_array是否正确获取到数据。修复SQL注入漏洞并添加调试
原代码存在SQL注入风险,同时添加调试信息帮你定位问题,修改delete.inc.php:<?php include "dbh.inc.php"; // 开启调试模式(上线后关闭) error_reporting(E_ALL); ini_set('display_errors', 1); if(isset($_GET['commentId'])) { $id = (int)$_GET['commentId']; // 使用预处理语句防注入 $delete = "DELETE FROM `commenttb` WHERE `commentId` = ?"; $stmt = mysqli_prepare($conn, $delete); mysqli_stmt_bind_param($stmt, "i", $id); $result = mysqli_stmt_execute($stmt); if ($result) { echo "删除成功,受影响行数:" . mysqli_affected_rows($conn); header("refresh:2; url=../test.php?success=successfully deleted"); } else { echo "SQL错误:" . mysqli_error($conn); header("refresh:2; url=../test.php?error=" . urlencode(mysqli_error($conn))); } }else { echo "未获取到commentId参数"; header("refresh:2; url=../test.php?error=missing commentId"); } ?>关于POST方法的正确用法
<a>标签不支持method="POST",如果要改用POST,需要把链接改成表单:<td> <form action="includes/delete.inc.php" method="POST" style="display:inline;"> <input type="hidden" name="commentId" value="<?php echo $row["commentId"]; ?>"> <button type="submit">Delete</button> </form> </td>同时把
delete.inc.php里的$_GET替换成$_POST。
内容的提问来源于stack exchange,提问作者MaxDex
相关产品推荐
相关产品推荐

