图片存入longblob字段报错求助:Undefined array key等问题排查
解决文件上传至LongBlob字段的错误问题
核心错误分析
- 文件上传检查用错数组:文件上传字段的信息存在
$_FILES而非$_POST,你用isset($_POST['image'])完全无法检测文件是否上传成功。 - 表单缺少提交按钮:HTML表单没有提交按钮,且PHP逻辑依赖
$_POST['submit']触发,导致文件处理代码从未执行,后续使用$image1/$image2时会出现空值错误。 - 变量未初始化:若查询
etudiant表无结果,$age变量未赋值,后续判断年龄会报错;文件处理代码未做错误校验,直接读取tmp_name会导致路径为空。 - SQL注入风险:直接将用户输入拼入SQL语句,存在严重安全隐患。
修复步骤
1. 修复HTML表单
添加提交按钮,确保表单能触发submit参数:
<form method="post" action="contact.php" enctype="multipart/form-data"> <?php if(isset($error)){ foreach($error as $error){ echo '<span class="error-msg">'.$error.'</span>'; }; }; ?> <div class="control-group"> <input type="text" class="form-control border-0 p-4" name="matricule" required placeholder="学号" /> <p class="help-block text-danger"></p> </div> <div class="control-group"> <input type="text" class="form-control border-0 p-4" name="residence" required placeholder="居住街区" /> <p class="help-block text-danger"></p> </div> <div class="drag-area"> <div class="icon"><i class="fas fa-cloud-upload-alt"></i></div> <header>拖拽上传您的身份证照片</header> <span>OR</span> <button type="button">选择文件 </button> <input type="file" name="image" hidden required > </div> <div class="drag-area1"> <div class="icon"><i class="fas fa-cloud-upload-alt"></i></div> <header class="header">拖拽上传您的缴费凭证照片</header> <span>OR</span> <button class="button" type="button">选择文件 </button> <input type="file" name="img" hidden class="input" required > </div> <!-- 添加提交按钮 --> <div class="control-group mt-4"> <button type="submit" name="submit" class="btn btn-primary">提交申请</button> </div> </form>
2. 修复PHP逻辑
调整逻辑顺序,先验证所有输入(包括文件),再处理数据库操作,使用预处理语句防止注入:
<?php @include 'connect.php'; $error = []; // 初始化错误数组 if($_SERVER['REQUEST_METHOD'] === "POST" && isset($_POST['submit'])){ // 1. 验证文本输入 $matricule = trim($_POST['matricule'] ?? ''); $residence = trim($_POST['residence'] ?? ''); if(empty($matricule) || empty($residence)){ $error[] = "学号和居住街区不能为空"; } // 2. 验证并处理文件上传 $image1 = null; if(isset($_FILES['image']) && $_FILES['image']['error'] === UPLOAD_ERR_OK){ $tmpPath = $_FILES['image']['tmp_name']; if(file_exists($tmpPath)){ $image1 = base64_encode(file_get_contents($tmpPath)); }else{ $error[] = "身份证照片上传失败,临时文件不存在"; } }else{ $error[] = "请上传身份证照片"; } $image2 = null; if(isset($_FILES['img']) && $_FILES['img']['error'] === UPLOAD_ERR_OK){ $tmpPath = $_FILES['img']['tmp_name']; if(file_exists($tmpPath)){ $image2 = base64_encode(file_get_contents($tmpPath)); }else{ $error[] = "缴费凭证照片上传失败,临时文件不存在"; } }else{ $error[] = "请上传缴费凭证照片"; } // 3. 所有验证通过后,处理数据库逻辑 if(empty($error)){ // 检查是否已提交过申请 $stmt = $conn->prepare("SELECT * FROM candidat WHERE MATRICULE = ?"); $stmt->bind_param("s", $matricule); $stmt->execute(); $result1 = $stmt->get_result(); if(mysqli_num_rows($result1) > 0){ $error[] = "您已提交过申请"; }else{ // 查询学生信息并计算年龄 $stmt = $conn->prepare("SELECT DATENAISSANCE FROM etudiant WHERE MATRICULE = ?"); $stmt->bind_param("s", $matricule); $stmt->execute(); $result = $stmt->get_result(); if(mysqli_num_rows($result) > 0){ $row = mysqli_fetch_assoc($result); $birthDate = new DateTime($row['DATENAISSANCE']); $today = new DateTime(); $age = $today->diff($birthDate)->y; if($age < 23){ // 插入数据到candidat表 $stmt = $conn->prepare("INSERT INTO candidat(MATRICULE, RESIDENCE, CNI, RECUEPAIEMENT) VALUES(?, ?, ?, ?)"); $stmt->bind_param("ssss", $matricule, $residence, $image1, $image2); if($stmt->execute()){ $error[] = "您的申请已成功提交"; }else{ $error[] = "申请提交失败:".$stmt->error; } }else{ $error[] = "抱歉,您年龄已超过22岁,无法申请住宿,您的年龄为".$age."岁"; } }else{ $error[] = "您未完成注册"; } } } } ?>
额外说明
- 文件上传验证:使用
$_FILES['xxx']['error'] === UPLOAD_ERR_OK是最可靠的文件上传成功判断方式,能覆盖文件过大、临时目录错误等多种异常。 - 预处理语句:所有SQL操作使用预处理语句绑定参数,彻底避免SQL注入风险。
- 变量初始化:提前初始化
$error、$image1、$image2等变量,防止未定义变量报错。 - 年龄计算:改用
DateTime类计算年龄,比DATEDIFF更准确(考虑闰年等情况)。
内容的提问来源于stack exchange,提问作者Sabou
相关产品推荐
相关产品推荐

