CodeIgniter跨表填充数据库数据时遇数组转字符串转换错误
Got it, let's break down exactly what's going wrong here and fix your CodeIgniter code step by step.
The Root Causes
You've got two critical issues in your saveassignment model function, plus a security risk to address:
- Early
returnkills your code execution: Thatreturn $query->result();line sends the query result back immediately, so none of the code after it (fetching the outcome, getting the username, or running the INSERT) ever runs. No wonder you're seeing weird behavior! - You're grabbing an array instead of a single value:
$query->result()returns an array of objects, even if there's only one matching row. When you try to stick that array into your INSERT statement, PHP tries to convert it to a string and spits out "Array" plus the conversion error. - SQL Injection Vulnerability: Directly plugging user input into your SQL queries is a huge security hole—attackers could easily manipulate these values to access or destroy your data.
Fixed Model Code
Here's the corrected version of your saveassignment function, with all issues resolved:
// saves user assignment in the backend database under 'submissions' table public function saveassignment($code, $assignment) { // Safely fetch the expected outcome using query binding to avoid injection $query = $this->db->query("SELECT expectedoutcome FROM assignments WHERE assignmentname = ?", [$assignment]); // Make sure we found a matching assignment first if ($query->num_rows() === 0) { return false; // Return false to signal no assignment found } // Get the single expected outcome value from the first (and only) row $expectedoutcome = $query->row()->expectedoutcome; // Get the logged-in user's username $username = $this->session->userdata('username'); // Safely insert the submission using query binding $this->db->query( "INSERT INTO submissions (accountid, assignmenttitle, assignment, expectedoutcome) VALUES (?, ?, ?, ?)", [$username, $assignment, $code, $expectedoutcome] ); // Return true if the insert was successful return $this->db->affected_rows() > 0; }
Bonus Improvements
For cleaner, more maintainable code, use CodeIgniter's Active Record class instead of raw SQL queries—it handles security and readability for you:
// Alternative: Using Active Record for the query and insert public function saveassignment($code, $assignment) { // Fetch expected outcome $this->db->select('expectedoutcome'); $this->db->where('assignmentname', $assignment); $query = $this->db->get('assignments'); if ($query->num_rows() === 0) { return false; } $expectedoutcome = $query->row()->expectedoutcome; $username = $this->session->userdata('username'); // Insert the submission $data = [ 'accountid' => $username, 'assignmenttitle' => $assignment, 'assignment' => $code, 'expectedoutcome' => $expectedoutcome ]; $this->db->insert('submissions', $data); return $this->db->affected_rows() > 0; }
You can also update your controller to handle the model's return value and give users better feedback:
else { $assignment = $this->input->post('assignmentname'); $code = $this->input->post('testcode'); $saveSuccess = $this->system->saveassignment($code, $assignment); if ($saveSuccess) { echo "Code Saved Successfully"; echo "<br /><a href='results'>View Results</a>"; } else { echo "Oops! We couldn't find that assignment or there was an error saving your submission."; } }
内容的提问来源于stack exchange,提问作者Quarismo
相关产品推荐
相关产品推荐

