PHP实现库存ID关联产品列表,刷新后保持选中状态
问题修复:库存ID传递与页面刷新状态保持
核心问题分析
- 库存列表的「详情」按钮未包裹表单,也未携带对应库存ID,点击后无法将ID传递到后端
$inventuraId全局变量未被正确赋值,fetchInventura()函数无法获取有效ID- 未通过URL参数保存选中状态,刷新页面后丢失当前选中的库存ID
- 直接拼接SQL存在注入风险,代码安全性不足
完整修复代码
1. 重构库存列表获取函数(移除全局变量)
<?php function fetchSeznamInventur($userCon) { $query = mysqli_query($userCon, "SELECT * FROM seznamInventur"); return mysqli_fetch_all($query, MYSQLI_ASSOC); // 返回结构化的库存数据数组 } ?>
2. 修复库存列表HTML渲染(添加表单传递ID)
<?php $inventories = fetchSeznamInventur($userCon); ?> <table border="1" class="invTable"> <thead> <th>日期</th> <th>ID</th> <th>名称</th> <th>操作</th> </thead> <?php foreach ($inventories as $inv) : ?> <tr> <td><?php echo htmlspecialchars($inv["createdate"])?></td> <td><?php echo htmlspecialchars($inv["id"]) ?></td> <td><?php echo htmlspecialchars($inv["name"])?></td> <td> <!-- 为每个库存项生成独立表单,传递对应ID --> <form method="get" action=""> <input type="hidden" name="inv_id" value="<?php echo $inv['id'] ?>"> <input type="submit" value="详情"> </form> </td> </tr> <?php endforeach; ?> </table>
3. 重构产品列表获取函数(用预处理语句防注入)
<?php function fetchInventura($userCon, $inventuraId) { // 使用预处理语句彻底避免SQL注入风险 $stmt = mysqli_prepare($userCon, "SELECT * FROM inv WHERE inventuraId = ?"); mysqli_stmt_bind_param($stmt, "i", $inventuraId); // "i"表示参数为整数类型 mysqli_stmt_execute($stmt); $result = mysqli_stmt_get_result($stmt); return mysqli_fetch_all($result, MYSQLI_ASSOC); } ?>
4. 产品列表渲染(处理URL参数,保持刷新状态)
<?php // 从URL参数读取选中的库存ID,刷新页面时参数会保留在地址栏 $selectedInvId = isset($_GET['inv_id']) ? (int)$_GET['inv_id'] : 0; $products = []; if ($selectedInvId > 0) { $products = fetchInventura($userCon, $selectedInvId); } ?> <table border="1"> <thead> <th>ID</th> <th>库存ID</th> <th>EAN</th> <th>数量</th> <th>更新日期</th> </thead> <?php foreach ($products as $product) : ?> <tr> <td><?php echo htmlspecialchars($product["id"])?></td> <td><?php echo htmlspecialchars($product["inventuraId"]) ?></td> <td><?php echo htmlspecialchars($product["ean"])?></td> <td><?php echo htmlspecialchars($product["quantity"])?></td> <td><?php echo htmlspecialchars($product["versiondate"])?></td> <!-- 保留原有隐藏字段 --> <td style="display: none;"><?php echo htmlspecialchars($product["name"])?></td> <td style="display: none;"><?php echo htmlspecialchars($product["plu"])?></td> <td style="display: none;"><?php echo htmlspecialchars($product["externalId"])?></td> <td style="display: none;"><?php echo htmlspecialchars($product["productId"])?></td> </tr> <?php endforeach; ?> </table>
关键修复点说明
- 使用
GET方法传递库存ID,地址栏会保留?inv_id=xxx参数,刷新页面时状态不会丢失 - 移除全局变量,改用函数参数传递数据库连接和ID,代码逻辑更清晰、健壮
- 用mysqli预处理语句处理SQL查询,彻底杜绝注入风险
- 用
htmlspecialchars()转义所有输出内容,防止XSS攻击 - 用
foreach遍历数据库结果数组,比计数式for循环更可靠,避免结果集遍历异常
内容的提问来源于stack exchange,提问作者Jiří Liška
相关产品推荐
相关产品推荐

