PHP点餐系统info.php中$id_bayar未定义错误解决求助
问题分析与解决方案
错误根源
- 变量未初始化:
$id_bayar仅在while循环内部定义,若用户无订单($count <= 0),循环不执行,变量未被创建,后续SQL查询调用时触发未定义警告。 - 语法不规范:原代码
if ($count>0)未加花括号,导致while循环不受if判断约束,语法逻辑存在隐患。 - 多订单逻辑漏洞:若用户有多条订单,
$id_bayar会被最后一条数据覆盖,仅能处理最后一个订单的凭证上传,不符合业务逻辑。 - SQL注入风险:直接将用户输入拼接到SQL语句中,存在严重安全隐患。
修复步骤
1. 初始化变量+规范语法
在循环前初始化$id_bayar,并给if判断补上花括号:
$count = mysqli_num_rows( $res ); $id_bayar = ''; // 提前初始化变量 if ( $count>0 ) { // 补上花括号,明确代码块范围 while( $row = mysqli_fetch_assoc( $res ) ) { // 原有订单数据赋值逻辑 $id_bayar = $row['id_bukti_bayar']; // ... 其他代码 } }
2. 处理无订单场景
在表格后添加无订单提示,避免后续逻辑空转:
</table> <br> <?php if ($count <= 0) { echo "<p class='text-center'>Anda belum memiliki pesanan.</p>"; } else { // 原有凭证查询及上传逻辑放在此处 } ?>
3. 修复SQL注入风险
改用mysqli预处理语句替代字符串拼接:
// 查询用户信息示例 $sql3 = "SELECT * FROM pelanggan WHERE username= ?"; $stmt = mysqli_prepare($conn, $sql3); mysqli_stmt_bind_param($stmt, "s", $username); mysqli_stmt_execute($stmt); $res3 = mysqli_stmt_get_result($stmt); $data_user = mysqli_fetch_assoc( $res3 ); // 查询订单信息示例 $sql = "SELECT * FROM tabel_pesanan JOIN pelanggan ON tabel_pesanan.id_pelanggan=pelanggan.id_pelanggan JOIN tabel_makanan ON tabel_makanan.id_makanan=tabel_pesanan.id_makanan WHERE pelanggan.id_pelanggan=?"; $stmt = mysqli_prepare($conn, $sql); mysqli_stmt_bind_param($stmt, "i", $id_user); mysqli_stmt_execute($stmt); $res = mysqli_stmt_get_result($stmt); $count = mysqli_num_rows( $res );
4. 优化多订单凭证上传逻辑
给每个订单添加独立的上传入口,避免仅处理最后一个订单:
// 在订单循环内部添加 $current_id_bayar = $row['id_bukti_bayar']; // 查询当前订单的凭证状态 $sql_bukti = "SELECT * FROM bukti_pembayaran WHERE id_bukti_bayar=?"; $stmt_bukti = mysqli_prepare($conn, $sql_bukti); mysqli_stmt_bind_param($stmt_bukti, "i", $current_id_bayar); mysqli_stmt_execute($stmt_bukti); $res_bukti = mysqli_stmt_get_result($stmt_bukti); $row_bukti = mysqli_fetch_assoc($res_bukti); $gambar_uploaded = !empty($row_bukti['gambar']); ?> <td data-header> <?php if (!$gambar_uploaded): ?> <form method='POST' action='uploadbukti.php' enctype='multipart/form-data' style='display: inline;'> <input type='file' name='image' required> <input type='hidden' name='id_bukti_bayar' value="<?php echo $current_id_bayar?>" /> <input type='Submit' class='btn-secondary' value='Upload Bukti'> </form> <?php else: ?> <span>Bukti Sudah Diupload</span> <?php endif; ?> </td>
完整修复后关键代码片段
<?php include( 'partials-front/menu.php' ); ?> <section class='food-menu'> <div class='container'> <h3 class='text-center'>Informasi Orderan</h3> </br></br> <p class='text-center'><a href='foods.php'>Tambah Pesananan +</a></p><br> <table class='demo-table responsive'> <thead> <tr> <th scope='col'>Nama</th> <th scope='col'>Pesanan</th> <th scope='col'>Harga</th> <th scope='col'>Jumlah</th> <th scope='col'>Status</th> <th scope='col'>Aksi</th> </tr> </thead> <?php $username = $_SESSION[ 'user' ]; // 预处理查询用户 $sql3 = "SELECT * FROM pelanggan WHERE username= ?"; $stmt = mysqli_prepare($conn, $sql3); mysqli_stmt_bind_param($stmt, "s", $username); mysqli_stmt_execute($stmt); $res3 = mysqli_stmt_get_result($stmt); $data_user = mysqli_fetch_assoc( $res3 ); $id_user = $data_user['id_pelanggan'] ?? ''; $id_bayar = ''; // 预处理查询订单 $sql = "SELECT * FROM tabel_pesanan JOIN pelanggan ON tabel_pesanan.id_pelanggan=pelanggan.id_pelanggan JOIN tabel_makanan ON tabel_makanan.id_makanan=tabel_pesanan.id_makanan WHERE pelanggan.id_pelanggan=?"; $stmt = mysqli_prepare($conn, $sql); mysqli_stmt_bind_param($stmt, "i", $id_user); mysqli_stmt_execute($stmt); $res = mysqli_stmt_get_result($stmt); $count = mysqli_num_rows( $res ); if ( $count>0 ) { while( $row = mysqli_fetch_assoc( $res ) ) { $nama = $row[ 'nama' ]; $makanan = $row[ 'title' ]; $harga = $row[ 'harga' ]; $jumlah = $row[ 'jumlah' ]; $total = $row [ 'total' ]; $status = $row[ 'status' ]; $current_id_bayar = $row[ 'id_bukti_bayar' ]; // 查询当前订单凭证状态 $sql_bukti = "SELECT * FROM bukti_pembayaran WHERE id_bukti_bayar=?"; $stmt_bukti = mysqli_prepare($conn, $sql_bukti); mysqli_stmt_bind_param($stmt_bukti, "i", $current_id_bayar); mysqli_stmt_execute($stmt_bukti); $res_bukti = mysqli_stmt_get_result($stmt_bukti); $row_bukti = mysqli_fetch_assoc($res_bukti); $gambar_uploaded = !empty($row_bukti['gambar']); ?> <tbody> <tr> <td data-header class='title'><?php echo $nama?></td> <td data-header><?php echo $makanan ?></td> <td data-header><?php echo $harga?></td> <td data-header><?php echo $jumlah?></td> <td data-header><?php echo $status?></td> <td data-header> <?php if (!$gambar_uploaded): ?> <form method='POST' action='uploadbukti.php' enctype='multipart/form-data' style='display: inline;'> <input type='file' name='image' required> <input type='hidden' name='id_bukti_bayar' value="<?php echo $current_id_bayar?>" /> <input type='Submit' class='btn-secondary' value='Upload Bukti'> </form> <?php else: ?> <span>Bukti Sudah Diupload</span> <?php endif; ?> </td> </tr> </tbody> <?php } } else { ?> <tbody> <tr> <td colspan='6' class='text-center'>Anda belum memiliki pesanan.</td> </tr> </tbody> <?php } ?> </table> <br> <?php if ($count > 0): ?> <h1> Transfer Ke Nomor rekening : 0111-01-058223-50-7 (BANK BRI)</h1> <?php endif; ?> <div class='clearfix'></div> </div> </section> <?php include( 'partials-front/footer.php' ); ?>
内容的提问来源于stack exchange,提问作者203 002 JONATHAN MARKUS SENAS
相关产品推荐
相关产品推荐

