PHP无法删除MySQL数据库行问题求助
Let’s break down exactly what’s going wrong here—your delete script is reporting success but not actually modifying the database because of a few critical, easy-to-fix issues.
1. The Root Cause: Broken URL Parameter in Your Delete Button
First, your delete link isn’t passing the task_id parameter correctly. Look at your button code:
echo "<td><a href='delete.php?=Delete" . $row['task_id']."'>Delete" . "</a>" . "</td></tr>" . "$record->ID";
This generates a URL like delete.php?=Delete123—there’s no parameter name for the task ID! $_GET['task_id'] in your delete script can’t find a value because the parameter isn’t named properly.
Fix the button code to pass the task_id explicitly:
echo "<td><a href='delete.php?task_id=" . $row['task_id'] . "'>Delete</a></td></tr>";
(Note: The trailing $record->ID was extra and would output raw text outside your HTML table—remove it.)
2. Your Delete Script Isn’t Actually Executing the SQL Query
Looking at your delete script, you define the $sql variable but never run it with mysqli_query! Plus there are inconsistent connection variables and missing error handling.
Fixed Delete Script (With Error Checking)
// First, validate the incoming task ID if (isset($_GET['task_id']) && is_numeric($_GET['task_id'])) { $task_id = $_GET['task_id']; // Replace $connect with your actual database connection variable (fix inconsistency!) $delete_query = "DELETE FROM Tasks WHERE task_id = $task_id"; $result = mysqli_query($connect, $delete_query); if ($result) { // Verify a row was actually deleted if (mysqli_affected_rows($connect) > 0) { echo "Successfully deleted"; } else { echo "No matching task found to delete (check if the task ID exists)"; } } else { // Show SQL error for debugging (remove in production!) echo "Error deleting task: " . mysqli_error($connect); } } else { echo "Invalid or missing task ID"; } // Close the same connection variable you used earlier mysqli_close($connect);
3. Critical Security Upgrade: Prevent SQL Injection
Right now, you’re directly inserting user input ($_GET['task_id']) into your SQL query—this is a huge security risk. Use prepared statements instead to sanitize input:
if (isset($_GET['task_id']) && is_numeric($_GET['task_id'])) { $task_id = $_GET['task_id']; // Prepared statement to avoid SQL injection $stmt = mysqli_prepare($connect, "DELETE FROM Tasks WHERE task_id = ?"); mysqli_stmt_bind_param($stmt, "i", $task_id); // "i" = integer type mysqli_stmt_execute($stmt); if (mysqli_stmt_affected_rows($stmt) > 0) { echo "Successfully deleted"; } else { echo "No matching task found to delete"; } mysqli_stmt_close($stmt); } else { echo "Invalid or missing task ID"; } mysqli_close($connect);
Why This Works
- The fixed button passes a valid
task_idparameter that your script can read. - We added checks to confirm the ID exists and is numeric before running the query.
- We verify that rows were actually affected (so you don’t get a false "success" message when no task matches the ID).
- Prepared statements eliminate SQL injection risks, which is essential for production code.
内容的提问来源于stack exchange,提问作者daniel fitton

