PHP OOP项目数据插入失败:点击保存后空白页无数据入库
问题:PHP OOP项目点击保存后页面空白,数据未写入数据库
这是我的第一个PHP OOP项目,采用面向对象模式开发。点击保存按钮尝试插入数据时,页面变为空白,且无数据写入数据库。我想坚持使用OOP方式解决,不想把PHP代码嵌入HTML结合JS处理。
index.php 文件代码
<?php include "items.class.php"; ?> <!DOCTYPE html> <html> <html lang = "en"> <head> <title> products </title> <link rel="stylesheet" href="http://code.jquery.com/ui/1.10.3/themes/smoothness/jquery-ui.css"/> <link rel="stylesheet" type="text/css" href="layout\css\style.css"/> <link rel="stylesheet" type="text/css" href="layout\css\bootstrap.css"/> <link rel="stylesheet" type="text/css" href="layout\css\fontawesome.min.css"/> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE-edge"> <meta name="viewport" content="width=device-width, initial-scale=1.0" > </head> <body class="body"> <nav class="navbar navbar-header navbar-dark bg-dark" style="font-family: Trebuchet MS, sans-serif;"> <a class="navbar-brand font-weight-bold h1" href="#" style="margin-left: 2rem; margin-top:1rem;">PRODUCTS LIST</a> <form action="<?php $item = new Items(); $item->insertItem(); ?>" method = "POST"> <input type="submit" value="Save" name="submit" class="button btn navbar-btn text-light bg-dark"> <span style="margin-top:0.5rem; margin-right:2rem;"> <a href="./index.php" class="button btn navbar-btn text-light bg-dark">Cancel</a> </span> </nav> <div clss="form-area"> <div class= "main" > <!-- sku - name - price --> <div class="labels-devider"> <label class="label text-light" >SKU</label> <input value="defaulted" disabled > </div> <div class="labels-devider"> <label class="label text-light">Name</label> <input type= "text" name="name" required> </div> <div class="labels-devider"> <label class="label text-light" >price($)</label> <input type="number" name="price" required> </div> <!-- typeswitcher --> <div class="labels-devider"> <label class="label text-light" style="width:130px;" >Type Switcher</label> <span class="selectpicker" > <select name="type" id="productType" style="width:200px;" required> <option selected >Select A Type:</option> <option value="DVD">DVD</option> <option value="Furniture">Furniture</option> <option value="Book">Book</option> </select> </span> </div> <!-- indivisual forms --> <div style= "margin-top:20px; "> <div id="DVD-area"> <label class="label text-light">Size (MB)</label> <input type="number" name = "size" id="size" > <p class="description">Please, provide size*</p> </div> <div id="Furniture-area"> <div class="labels-devider"> <label class="label text-light">Height (CM)</label> <input type="number" name = "height" id="height"> <p class="description">Please, provide height*</p> </div> <div class="labels-devider"> <label class="label text-light">Width (CM)</label> <input type="number" id="width" name="width"> <p class="description">Please, provide width*</p> </div> <div class="labels-devider"> <label class="label text-light">Length (CM)</label> <input type="number" id="length" name="length" > <p class="description" >Please, provide length*</p> </div> </div> <div id="Book-area"> <label class="label text-light">Weight (KH)</label> <input type="number" id="weight" weight="weight" > <p class="description">Please, provide weight*</p> </div> </div> </div> </div> <footer class="foot"> <p class="text-center py-3 bg-dark shadow">Scandiweb Test Assignment - done by rima- <br> </footer> <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.5.0/jquery.min.js"></script> <script type="text/javascript"> $("#DVD-area").hide(); $("#Furniture-area").hide(); $("#Book-area").hide(); $('#productType').change(function(){ switch($('#productType').find('option:selected').text()){ case "DVD" : $("#DVD-area").show(); $("#Furniture-area").hide(); $("#Book-area").hide(); $("#size").attr('required', true); break; case "Furniture" : $("#DVD-area").hide(); $("#Furniture-area").show(); $("#Book-area").hide(); $("#height").attr('required', true); $("#width").attr('required', true); $("#length").attr('required', true); break; case "Book" : $("#DVD-area").hide(); $("#Furniture-area").hide(); $("#Book-area").show(); $("#weight").attr('required', true); break; default: $("#DVD-area").hide(); $("#Furniture-area").hide(); $("#Book-area").hide(); }}); </script> </body> </html>
items.class.php 文件代码
<?php include "dbh.class.php"; Class Items extends Dbh{ Public function getItems(){ //fetch items $sql = "SELECT * FROM items"; $stmt = $this->connect()->query($sql); return $stmt; } Public function insertItem(){ if(isset($_POST['submit'])){ if(isset($_POST['name']) && isset($_POST['price']) && isset($_POST['type'])){ switch(strtolower($_POST['type'])){ case "dvd": $value = $_POST['size']; $value_2 = null; $value_3 = null; break; case "furniture": $value = $_POST['height']; $value_2 = $_POST['width']; $value_3 = $_POST['length']; break; case "book": $value = $_POST['height']; $value_2 = $_POST['width']; $value_3 = $_POST['length']; break; } $name = strval($_POST['name']); $type= strval($_POST['type']); $price= $_POST['price']; $sql = "INSERT INTO items (name, price, value, value_2, value_3, type) VALUES ($name, $price, $value, $value_2 , $value_3, $type"; $this->connect()->exec($sql); } } } }
问题排查与修复步骤
1. 表单Action属性错误
当前表单的action属性直接执行insertItem()方法,导致页面加载时就调用该方法,且无返回内容,引发页面空白。
修复:
修改index.php顶部代码,判断POST提交后再调用插入方法:
<?php error_reporting(E_ALL); ini_set('display_errors', 1); include "items.class.php"; if(isset($_POST['submit'])){ $item = new Items(); $item->insertItem(); header("Location: index.php"); exit; } ?>
同时修改表单的action属性:
<form action="" method="POST">
2. SQL语句语法错误
插入语句缺少闭合右括号,且字符串字段未用单引号包裹,导致数据库执行失败。
修复:
$sql = "INSERT INTO items (name, price, value, value_2, value_3, type) VALUES ('$name', $price, $value, $value_2, $value_3, '$type')";
3. Book类型参数错误
switch分支中Book类型错误引用了height/width/length,应改为weight。
修复:
case "book": $value = $_POST['weight']; $value_2 = null; $value_3 = null; break;
4. Book区域输入字段name属性错误
index.php中Book区域的input字段weight="weight"应为name="weight"。
修复:
<input type="number" id="weight" name="weight" >
5. 解决SQL注入风险
直接拼接用户输入存在注入风险,改用预处理语句:
$sql = "INSERT INTO items (name, price, value, value_2, value_3, type) VALUES (?, ?, ?, ?, ?, ?)"; $stmt = $this->connect()->prepare($sql); $stmt->execute([$name, $price, $value, $value_2, $value_3, $type]);
内容的提问来源于stack exchange,提问作者Rima T
相关产品推荐
相关产品推荐

