You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP更新记录按钮无法传递患者ID至编辑页面的求助

Fixing Patient Edit Page Data Loading Issue

Alright, let's figure out why your patient edit page isn't loading the data and fix it up properly. The core problems are related to variable parsing in your HTML output and unsafe SQL practices. Here's the breakdown and corrected code:

Key Issues in Your Original Code

  1. Unparsed Variables in HTML Strings
    In both patients.php and patientEdit.php, you're using single quotes to wrap HTML content that contains PHP variables. PHP doesn't parse variables inside single-quoted strings, so values like $row[patientID] and $row[email] are being sent as literal text instead of the actual patient data.

  2. SQL Injection Vulnerability
    Directly inserting $_POST["pid"] into your SQL query is a major security risk, and it can also lead to unexpected behavior if the ID contains special characters.

  3. Lack of Error Checking
    You don't have any checks to verify if the query ran successfully or if any results were returned, making it hard to debug what's going wrong.


Corrected patients.php Code

The main fix here is properly passing the patient ID in the hidden form field by using string concatenation to insert the variable value:

<?php
require_once 'includes/dbh.inc.php';
$result = mysqli_query($conn,"SELECT * FROM patientProfile ORDER BY patientLastName ASC");

echo "<table class=table table-striped table-sm> 
    <tr> 
        <th>Last Name</th> 
        <th>Name</th> 
        <th>Gender</th> 
        <th>Age</th> 
        <th>Medical Plan</th> 
        <th>Record Number</th> 
        <th></th> 
    </tr>";

while($row = mysqli_fetch_array($result)) {
    echo "<tr>";
    echo "<td>" . $row['patientLastName'] . "</td>";
    echo "<td>" . $row['patientName'] . "</td>";
    echo "<td>" . $row['patientGender'] . "</td>";
    echo "<td>" . $row['patientAge'] . "</td>";
    echo "<td>" . $row['medicalPlan'] . "</td>";
    echo "<td>" . $row['patientID'] . "</td>";
    // Fix: Use string concatenation to pass the actual patient ID
    echo '<td>
            <form method="POST" action="patientEdit.php">
                <input type="hidden" name="pid" value="' . $row['patientID'] . '">
                <input type="submit" name="submit_btn" value="Update">
            </form>
        </td>';
    echo "</tr>";
}
echo "</table>";
mysqli_close($conn);
?>

Corrected patientEdit.php Code

Here we use prepared statements to safely query the database, fix the email input variable parsing, and add error checking:

<?php
require_once 'includes/dbh.inc.php';

if (isset($_POST["submit_btn"]) && isset($_POST["pid"])) {
    $patientId = $_POST["pid"];
    
    // Use prepared statement to prevent SQL injection
    $stmt = $conn->prepare("SELECT * FROM patientProfile WHERE patientID = ?");
    // Bind parameter: "i" means integer (use "s" if patientID is a string)
    $stmt->bind_param("i", $patientId);
    $stmt->execute();
    $result = $stmt->get_result();

    if ($result->num_rows === 0) {
        echo "No patient found with this record number.";
    } else {
        echo "<table class=table table-striped table-sm> 
            <tr> 
                <th>Record Number</th> 
                <th>Last Name</th> 
                <th>Name</th> 
                <th>Gender</th> 
                <th>Age</th> 
                <th>Email</th> 
            </tr>";
        
        while($row = $result->fetch_assoc()) {
            echo "<tr>";
            echo "<td>" . $row['patientID'] . "</td>";
            echo "<td>" . $row['patientLastName'] . "</td>";
            echo "<td>" . $row['patientName'] . "</td>";
            echo "<td>" . $row['patientGender'] . "</td>";
            echo "<td>" . $row['patientAge'] . "</td>";
            // Fix: Parse email variable and escape it to prevent XSS
            echo "<td><input type='text' name='changeEmail' value='" . htmlspecialchars($row['email']) . "'></td>";
            echo "</tr>";
        }
        echo "</table>";
    }
    $stmt->close();
} else {
    echo "Invalid request: Missing patient ID.";
}
mysqli_close($conn);
?>

Additional Notes

  • Security: Using prepared statements is critical to protect your database from SQL injection attacks. Always avoid directly inserting user input into SQL queries.
  • XSS Protection: The htmlspecialchars() function ensures that any special characters in the patient's email are escaped, preventing cross-site scripting (XSS) attacks.
  • Debugging: If you still run into issues, you can add echo mysqli_error($conn); after executing a query to see any database errors that might be occurring.

内容的提问来源于stack exchange,提问作者Sloth86x

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:27:17