HTML表单与PHP数据插入功能失效问题排查求助
Fixing Your Student Data Insertion Issue
Let's break down the problems in your code and fix them step by step—no more guessing why the INSERT isn't working!
First, the Critical SQL Syntax Errors
Your INSERT query has two obvious syntax blunders that are immediately breaking the functionality:
- You wrapped column names in single quotes (
')—MySQL uses backticks (`) for column/table names (or nothing if they don’t have special characters), while single quotes are only for string values. - You missed a closing single quote after
$idklasyin theVALUESsection—this leaves your query incomplete.
Second, Severe SQL Injection Risk
Directly shoving user input from $_POST into your SQL query is a massive security gap. Always use prepared statements to block attackers from messing with your database.
Third, Quality-of-Life Improvements
- Set the database connection charset to match your page’s UTF-8 encoding to avoid weird character garbling.
- Rearrange your form elements so labels come before inputs (it’s more intuitive for users).
- Add specific MySQL error reporting to debug future issues faster.
Fixed Code
<html> <head> <meta charset="utf-8"> </head> <body> <h3>Wpisz ucznia</h3> <form method="POST"> Nazwisko<br> <input type="text" name="nazwisko" required /><br> Imie<br> <input type="text" name="imie" required /><br> Średnia ocen<br> <input type="text" name="srednia" required /><br> idklasy<br> <input type="text" name="idklasy" required /><br> <input type="submit" name="wpisz" value="Dodaj"> </form> <?php // Establish database connection $baza = mysqli_connect("localhost", "root", "", "szkoła") or die("Wystąpił błąd połączenia z bazą"); // Match charset to page encoding mysqli_set_charset($baza, 'utf8'); if (isset($_POST["wpisz"])) { // Use prepared statement to avoid SQL injection $stmt = mysqli_prepare($baza, "INSERT INTO uczen (Nazwisko, Imie, Srednia_ocen, id_klasy) VALUES (?, ?, ?, ?)"); mysqli_stmt_bind_param($stmt, "ssdi", $nazwisko, $imie, $srednia, $idklasy); // Assign and sanitize input values $nazwisko = $_POST['nazwisko']; $imie = $_POST['imie']; $srednia = (float)$_POST['srednia']; // Cast to float for grade average $idklasy = (int)$_POST['idklasy']; // Cast to int for class ID // Execute the query if (mysqli_stmt_execute($stmt)) { echo "Rekord został dodany poprawnie"; } else { // Show specific error for debugging echo "Błąd, nie udało się dodać nowego rekordu: " . mysqli_error($baza); } // Clean up statement mysqli_stmt_close($stmt); } // Fetch and display student count $kw = "SELECT * FROM uczen"; $niewynik = mysqli_query($baza, $kw); $liczba = mysqli_num_rows($niewynik); echo "<br> Obecnie w szkole jest " . $liczba . " uczniów."; // Close database connection mysqli_close($baza); ?> </body> </html>
Key Fixes Explained:
- SQL Syntax Corrected: Fixed the column name quoting issue and added the missing closing quote (though we replaced direct variable insertion with prepared statements for better security anyway).
- Prepared Statements: Used
mysqli_prepare,mysqli_stmt_bind_param, andmysqli_stmt_executeto safely handle user input—no more SQL injection risks. We also casted values to match typical database column types (float for grades, int for class IDs). - Charset Consistency: Added
mysqli_set_charset($baza, 'utf8')to make sure Polish characters display correctly. - Form Polish: Rearranged labels/inputs and added
requiredto ensure users fill in all fields before submitting. - Debugging Help: Added
mysqli_error($baza)to show exact MySQL errors, which will help you troubleshoot any remaining issues (like mismatched column types in your database).
内容的提问来源于stack exchange,提问作者Robix
相关产品推荐
相关产品推荐

