PHP更新记录按钮无法传递患者ID至编辑页面的求助
Alright, let's figure out why your patient edit page isn't loading the data and fix it up properly. The core problems are related to variable parsing in your HTML output and unsafe SQL practices. Here's the breakdown and corrected code:
Key Issues in Your Original Code
Unparsed Variables in HTML Strings
In bothpatients.phpandpatientEdit.php, you're using single quotes to wrap HTML content that contains PHP variables. PHP doesn't parse variables inside single-quoted strings, so values like$row[patientID]and$row[email]are being sent as literal text instead of the actual patient data.SQL Injection Vulnerability
Directly inserting$_POST["pid"]into your SQL query is a major security risk, and it can also lead to unexpected behavior if the ID contains special characters.Lack of Error Checking
You don't have any checks to verify if the query ran successfully or if any results were returned, making it hard to debug what's going wrong.
Corrected patients.php Code
The main fix here is properly passing the patient ID in the hidden form field by using string concatenation to insert the variable value:
<?php require_once 'includes/dbh.inc.php'; $result = mysqli_query($conn,"SELECT * FROM patientProfile ORDER BY patientLastName ASC"); echo "<table class=table table-striped table-sm> <tr> <th>Last Name</th> <th>Name</th> <th>Gender</th> <th>Age</th> <th>Medical Plan</th> <th>Record Number</th> <th></th> </tr>"; while($row = mysqli_fetch_array($result)) { echo "<tr>"; echo "<td>" . $row['patientLastName'] . "</td>"; echo "<td>" . $row['patientName'] . "</td>"; echo "<td>" . $row['patientGender'] . "</td>"; echo "<td>" . $row['patientAge'] . "</td>"; echo "<td>" . $row['medicalPlan'] . "</td>"; echo "<td>" . $row['patientID'] . "</td>"; // Fix: Use string concatenation to pass the actual patient ID echo '<td> <form method="POST" action="patientEdit.php"> <input type="hidden" name="pid" value="' . $row['patientID'] . '"> <input type="submit" name="submit_btn" value="Update"> </form> </td>'; echo "</tr>"; } echo "</table>"; mysqli_close($conn); ?>
Corrected patientEdit.php Code
Here we use prepared statements to safely query the database, fix the email input variable parsing, and add error checking:
<?php require_once 'includes/dbh.inc.php'; if (isset($_POST["submit_btn"]) && isset($_POST["pid"])) { $patientId = $_POST["pid"]; // Use prepared statement to prevent SQL injection $stmt = $conn->prepare("SELECT * FROM patientProfile WHERE patientID = ?"); // Bind parameter: "i" means integer (use "s" if patientID is a string) $stmt->bind_param("i", $patientId); $stmt->execute(); $result = $stmt->get_result(); if ($result->num_rows === 0) { echo "No patient found with this record number."; } else { echo "<table class=table table-striped table-sm> <tr> <th>Record Number</th> <th>Last Name</th> <th>Name</th> <th>Gender</th> <th>Age</th> <th>Email</th> </tr>"; while($row = $result->fetch_assoc()) { echo "<tr>"; echo "<td>" . $row['patientID'] . "</td>"; echo "<td>" . $row['patientLastName'] . "</td>"; echo "<td>" . $row['patientName'] . "</td>"; echo "<td>" . $row['patientGender'] . "</td>"; echo "<td>" . $row['patientAge'] . "</td>"; // Fix: Parse email variable and escape it to prevent XSS echo "<td><input type='text' name='changeEmail' value='" . htmlspecialchars($row['email']) . "'></td>"; echo "</tr>"; } echo "</table>"; } $stmt->close(); } else { echo "Invalid request: Missing patient ID."; } mysqli_close($conn); ?>
Additional Notes
- Security: Using prepared statements is critical to protect your database from SQL injection attacks. Always avoid directly inserting user input into SQL queries.
- XSS Protection: The
htmlspecialchars()function ensures that any special characters in the patient's email are escaped, preventing cross-site scripting (XSS) attacks. - Debugging: If you still run into issues, you can add
echo mysqli_error($conn);after executing a query to see any database errors that might be occurring.
内容的提问来源于stack exchange,提问作者Sloth86x

