You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

图片存入longblob字段报错求助:Undefined array key等问题排查

解决文件上传至LongBlob字段的错误问题

核心错误分析

  • 文件上传检查用错数组:文件上传字段的信息存在$_FILES而非$_POST,你用isset($_POST['image'])完全无法检测文件是否上传成功。
  • 表单缺少提交按钮:HTML表单没有提交按钮,且PHP逻辑依赖$_POST['submit']触发,导致文件处理代码从未执行,后续使用$image1/$image2时会出现空值错误。
  • 变量未初始化:若查询etudiant表无结果,$age变量未赋值,后续判断年龄会报错;文件处理代码未做错误校验,直接读取tmp_name会导致路径为空。
  • SQL注入风险:直接将用户输入拼入SQL语句,存在严重安全隐患。

修复步骤

1. 修复HTML表单

添加提交按钮,确保表单能触发submit参数:

<form method="post" action="contact.php" enctype="multipart/form-data">
    <?php
        if(isset($error)){
            foreach($error as $error){
                echo '<span class="error-msg">'.$error.'</span>';
            };
        };
    ?>

    <div class="control-group">
        <input type="text" class="form-control border-0 p-4" name="matricule" required placeholder="学号" />
        <p class="help-block text-danger"></p>
    </div>
    <div class="control-group">
        <input type="text" class="form-control border-0 p-4" name="residence" required placeholder="居住街区" />
        <p class="help-block text-danger"></p>
    </div>
    <div class="drag-area">
        <div class="icon"><i class="fas fa-cloud-upload-alt"></i></div>
        <header>拖拽上传您的身份证照片</header>
        <span>OR</span>
        <button type="button">选择文件 </button>
        <input type="file" name="image" hidden required >
    </div>

    <div class="drag-area1">
        <div class="icon"><i class="fas fa-cloud-upload-alt"></i></div>
        <header class="header">拖拽上传您的缴费凭证照片</header>
        <span>OR</span>
        <button class="button" type="button">选择文件 </button>
        <input type="file" name="img" hidden class="input" required >   
    </div>
    <!-- 添加提交按钮 -->
    <div class="control-group mt-4">
        <button type="submit" name="submit" class="btn btn-primary">提交申请</button>
    </div>
</form>

2. 修复PHP逻辑

调整逻辑顺序,先验证所有输入(包括文件),再处理数据库操作,使用预处理语句防止注入:

<?php
@include 'connect.php';
$error = []; // 初始化错误数组

if($_SERVER['REQUEST_METHOD'] === "POST" && isset($_POST['submit'])){ 
    // 1. 验证文本输入
    $matricule = trim($_POST['matricule'] ?? '');
    $residence = trim($_POST['residence'] ?? '');
    if(empty($matricule) || empty($residence)){
        $error[] = "学号和居住街区不能为空";
    }

    // 2. 验证并处理文件上传
    $image1 = null;
    if(isset($_FILES['image']) && $_FILES['image']['error'] === UPLOAD_ERR_OK){
        $tmpPath = $_FILES['image']['tmp_name'];
        if(file_exists($tmpPath)){
            $image1 = base64_encode(file_get_contents($tmpPath));
        }else{
            $error[] = "身份证照片上传失败,临时文件不存在";
        }
    }else{
        $error[] = "请上传身份证照片";
    }

    $image2 = null;
    if(isset($_FILES['img']) && $_FILES['img']['error'] === UPLOAD_ERR_OK){
        $tmpPath = $_FILES['img']['tmp_name'];
        if(file_exists($tmpPath)){
            $image2 = base64_encode(file_get_contents($tmpPath));
        }else{
            $error[] = "缴费凭证照片上传失败,临时文件不存在";
        }
    }else{
        $error[] = "请上传缴费凭证照片";
    }

    // 3. 所有验证通过后,处理数据库逻辑
    if(empty($error)){
        // 检查是否已提交过申请
        $stmt = $conn->prepare("SELECT * FROM candidat WHERE MATRICULE = ?");
        $stmt->bind_param("s", $matricule);
        $stmt->execute();
        $result1 = $stmt->get_result();
        if(mysqli_num_rows($result1) > 0){
            $error[] = "您已提交过申请";
        }else{
            // 查询学生信息并计算年龄
            $stmt = $conn->prepare("SELECT DATENAISSANCE FROM etudiant WHERE MATRICULE = ?");
            $stmt->bind_param("s", $matricule);
            $stmt->execute();
            $result = $stmt->get_result();
            if(mysqli_num_rows($result) > 0){
                $row = mysqli_fetch_assoc($result);
                $birthDate = new DateTime($row['DATENAISSANCE']);
                $today = new DateTime();
                $age = $today->diff($birthDate)->y;

                if($age < 23){
                    // 插入数据到candidat表
                    $stmt = $conn->prepare("INSERT INTO candidat(MATRICULE, RESIDENCE, CNI, RECUEPAIEMENT) VALUES(?, ?, ?, ?)");
                    $stmt->bind_param("ssss", $matricule, $residence, $image1, $image2);
                    if($stmt->execute()){
                        $error[] = "您的申请已成功提交";
                    }else{
                        $error[] = "申请提交失败:".$stmt->error;
                    }
                }else{
                    $error[] = "抱歉,您年龄已超过22岁,无法申请住宿,您的年龄为".$age."岁";
                }
            }else{
                $error[] = "您未完成注册";
            }
        }
    }
}
?>

额外说明

  • 文件上传验证:使用$_FILES['xxx']['error'] === UPLOAD_ERR_OK是最可靠的文件上传成功判断方式,能覆盖文件过大、临时目录错误等多种异常。
  • 预处理语句:所有SQL操作使用预处理语句绑定参数,彻底避免SQL注入风险。
  • 变量初始化:提前初始化$error、$image1、$image2等变量,防止未定义变量报错。
  • 年龄计算:改用DateTime类计算年龄,比DATEDIFF更准确(考虑闰年等情况)。

内容的提问来源于stack exchange,提问作者Sabou

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 05:10:42