PHP中如何将一个函数的$path变量传递到另一个函数?
解决$path变量传递及未定义错误的方案
问题原因
你在upload_image里声明了global $path,但complaints函数里没有引用这个全局变量,所以会触发未定义变量错误。另外,全局变量的使用本身容易引发作用域混乱,不推荐作为常规解决方案。
推荐方案:返回值+参数传递(规避全局变量)
修改upload_image函数,成功时返回生成的路径,失败时返回false;调用complaints时将路径作为参数传入:
function upload_image($table, $image) { $path = 'complaints/'.date("d-m-Y").'-'.time().'-'.rand(10000, 100000) . '.jpg'; if(file_put_contents($path, base64_decode($_POST['image']))){ // 用预处理语句避免SQL注入 $stmt = $this->connect->prepare("INSERT INTO complaints (path) VALUES (?)"); $stmt->bind_param("s", $path); if($stmt->execute()){ return $path; // 返回生成的路径 } else { return false; } } else { return false; } } function complaints($table, $complaints, $path) // 添加$path参数 { $complaints = $this->prepareData($complaints); // 用预处理语句避免SQL注入 $stmt = $this->connect->prepare("UPDATE " . $table . " SET user_complaints = ? WHERE path = ?"); $stmt->bind_param("ss", $complaints, $path); if($stmt->execute()){ return true; } else { return false; } } // 调用示例 $uploadPath = $yourInstance->upload_image('complaints', $image); if($uploadPath !== false){ $yourInstance->complaints('complaints', $userComplaints, $uploadPath); }
临时修复:正确使用全局变量(不推荐)
如果一定要保留全局变量的写法,需要在complaints函数里也声明global $path:
function complaints($table, $complaints) { global $path; // 添加此行,引用全局变量 $complaints = $this->prepareData($complaints); $this->sql = "UPDATE " . $table . " SET user_complaints = '".$complaints."' WHERE path = '".$path."' "; if (mysqli_query($this->connect, $this->sql)) { return true; } else return false; }
重要提醒:防范SQL注入
原代码直接将变量拼接进SQL语句,存在严重的SQL注入风险。推荐方案中已改用MySQLi预处理语句,这是更安全的写法,建议优先采用。
内容的提问来源于stack exchange,提问作者Paul Angelo Derige
相关产品推荐
相关产品推荐

