PHP+MySQL CURD应用更新功能失效及无错误提示问题求助
CURD应用更新功能失效问题排查与修复
我用PHP和MySQL开发了一个CURD应用,新增、读取、删除功能都能正常运行,但更新功能完全失效。点击更新按钮后会直接跳转到display.php页面,update.php根本没有正常执行,也没有任何错误提示。以下是相关代码:
display.php代码
<?php include 'conc.php'; // $username = $_POST["username"]; // $password = $_POST["password"]; $q = "select * from cued_data"; $query = mysqli_query($con , $q); ?> <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>display data</title> <link rel="stylesheet" href="curd.css"> </head> <body> <div class="container"> <h1>display Table Data</h1> <table class="table"> <tr> <th>Id</th> <th>Username</th> <th>Password</th> <th>Delete</th> <th>Update</th> </tr> <?php include 'conc.php'; $q = "select * from cued_data"; $query = mysqli_query($con , $q); while($res = mysqli_fetch_array($query)){ ?> <tr> <td> <?php echo $res['id']; ?> </td> <td> <?php echo $res['name']; ?> </td> <td> <?php echo $res['password']; ?> </td> <td><button class="dlt"> <a href="delete.php?id= <?php echo $res['id']; ?>" > Delete: </a> </button> </td> <td><button class="dlt"> <a href="update.html?id= <?php echo $res['id']; ?>" > Update: </a> </button> </td> </tr> <?php } ?> </table> </div> </body> </html>
update.php代码
<?php include "conc.php"; include "display.php"; $id = $_GET["id"]; # i think error in this section $username = $_POST["name"]; $password = $_POST["password"]; // $q = "delete from `cued_data` where id = $id" ; $msql= " update cued_data set id ='$id', name = '$username', password = '$password' where id = '$id' "; $query = mysqli_query($con, $msql); header("location:display.php"); ?>
delete.php代码
<?php include "conc.php"; $id = $_GET["id"]; $q = "delete from `cued_data` where id = $id" ; $query = mysqli_query($con, $q); header("location:display.php"); ?>
问题根源及修复方案
1. 核心问题分析
- 更新链接错误:display.php里更新按钮指向静态页面
update.html,无法处理表单提交和数据库更新逻辑;且点击链接是GET请求,根本不会触发POST数据传递。 - update.php逻辑混乱:
- 引入
display.php导致页面先输出HTML内容,后续header()跳转因已有输出失效(HTTP头必须在任何内容输出前发送)。 - 直接获取
$_POST数据但未判断请求方式,GET请求下$_POST为空,导致SQL语句变量缺失。 - SQL语句更新了主键
id字段,完全没必要还可能引发数据库约束错误。 - 未使用预处理语句,存在严重SQL注入风险。
- 引入
2. 分步修复
第一步:修改display.php的更新链接
把更新按钮的href从update.html?id=<?php echo $res['id']; ?>改成update_form.php?id=<?php echo $res['id']; ?>,需要一个带表单的页面让用户输入更新内容。
第二步:创建update_form.php(更新表单页面)
根据ID查询原有数据并展示表单,提交后将数据传给update.php处理:
<?php // 开启错误提示方便调试 error_reporting(E_ALL); ini_set('display_errors', 1); include 'conc.php'; $id = $_GET['id']; // 查询当前数据 $q = "select * from cued_data where id = $id"; $query = mysqli_query($con, $q); $res = mysqli_fetch_array($query); ?> <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>Update Data</title> <link rel="stylesheet" href="curd.css"> </head> <body> <div class="container"> <h1>Update Data</h1> <form action="update.php" method="post"> <!-- 隐藏字段传递ID --> <input type="hidden" name="id" value="<?php echo $res['id']; ?>"> <div> <label for="name">Username:</label> <input type="text" id="name" name="name" value="<?php echo $res['name']; ?>" required> </div> <div> <label for="password">Password:</label> <input type="text" id="password" name="password" value="<?php echo $res['password']; ?>" required> </div> <button type="submit">Update</button> </form> </div> </body> </html>
第三步:重构update.php
去除无效引入,只处理POST请求,使用预处理语句防止注入:
<?php // 开启错误提示方便调试 error_reporting(E_ALL); ini_set('display_errors', 1); include "conc.php"; // 只处理POST请求,防止直接访问 if ($_SERVER['REQUEST_METHOD'] !== 'POST') { header("location:display.php"); exit; } $id = $_POST["id"]; $username = $_POST["name"]; $password = $_POST["password"]; // 使用预处理语句执行更新,避免SQL注入 $stmt = $con->prepare("UPDATE cued_data SET name = ?, password = ? WHERE id = ?"); // 绑定参数:s=字符串,s=字符串,i=整数 $stmt->bind_param("ssi", $username, $password, $id); $stmt->execute(); // 跳转回展示页面 header("location:display.php"); exit; ?>
第四步:开启全局错误提示
在所有PHP文件开头添加以下代码,方便后续调试:
error_reporting(E_ALL); ini_set('display_errors', 1);
内容的提问来源于stack exchange,提问作者Gaurav Singh karki
相关产品推荐
相关产品推荐

