如何通过表单提交的数据更新数据库?PHP编辑页代码问题求助
问题分析与修复方案
现有代码的核心问题
- 提交按钮类型错误:当前按钮是
type="button",点击不会触发表单提交,需要改为type="submit" - 缺少POST请求处理逻辑:没有监听表单提交事件,也没有对应的数据更新逻辑
- 存在SQL注入风险:查询语句直接拼接
$_GET['id'],没有使用预处理 - HTML结构不规范:
form标签放在<tr>内部,不符合DOM结构规范 - 文本域显示异常:
<textarea>默认值多了一对单引号,会导致加载时额外显示引号
修复步骤
1. 新增PDO更新函数
新增可防止注入的预处理更新函数,替换原有直接拼接SQL的逻辑
2. 新增POST提交处理逻辑
页面加载时先判断是否有表单提交,有则执行更新操作,成功后跳转回列表/详情页
3. 修正表单HTML结构与属性
完整修复后代码
<?php // 数据库连接公共配置,避免重复定义 function getPdo() { $host = 'localhost'; $db = 'netland'; $user = 'root'; $pass = ''; $dsn = "mysql:host=$host;dbname=$db;charset=utf8mb4"; $options = [ PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION, PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC, PDO::ATTR_EMULATE_PREPARES => false, ]; try { return new PDO($dsn, $user, $pass, $options); } catch (\PDOException $e) { throw new \PDOException($e->getMessage(), (int)$e->getCode()); } } // 预处理查询单条数据,避免注入 function getSerieById($id) { $pdo = getPdo(); $stmt = $pdo->prepare("SELECT * FROM series WHERE id = ?"); $stmt->execute([$id]); return $stmt->fetch(); } // 预处理更新数据 function updateSerie($id, $has_won_awards, $seasons, $country, $language, $description) { $pdo = getPdo(); $sql = "UPDATE series SET has_won_awards = ?, seasons = ?, country = ?, language = ?, description = ? WHERE id = ?"; $stmt = $pdo->prepare($sql); return $stmt->execute([$has_won_awards, $seasons, $country, $language, $description, $id]); } $id = $_GET['id'] ?? null; if (!$id) { die("参数错误,缺少剧集ID"); } // 处理表单提交 if ($_SERVER['REQUEST_METHOD'] === 'POST') { // 接收表单数据,可自行加校验逻辑 $has_won_awards = $_POST['has_won_awards']; $seasons = $_POST['seasons']; $country = $_POST['country']; $language = $_POST['language']; $description = $_POST['description']; // 执行更新 if (updateSerie($id, $has_won_awards, $seasons, $country, $language, $description)) { // 更新成功跳回列表页,也可以跳转到详情页 header("Location: index.php"); exit; } else { echo "更新失败,请重试"; } } // 查询原有数据渲染表单 $row = getSerieById($id); if (!$row) { die("未找到对应剧集数据"); } ?> <a href='index.php'>返回</a> <h1><?php echo $row['title'] . ' - ' . $row['rating'] ?></h1> <!-- form移到table外面,提交后仍带id参数 --> <form action='?id=<?php echo $id ?>' method='POST'> <table> <tr> <th>获奖情况</th> <td><input type='text' name='has_won_awards' value='<?php echo $row['has_won_awards'] ?>'></td> </tr> <tr> <th>季数</th> <td><input type='text' name='seasons' value='<?php echo $row['seasons'] ?>'></td> </tr> <tr> <th>国家</th> <td><input type='text' name='country' value='<?php echo $row['country'] ?>'></td> </tr> <tr> <th>语言</th> <td><input type='text' name='language' value='<?php echo $row['language'] ?>'></td> </tr> </table> <!-- 去掉多余的单引号 --> <textarea rows='10' cols='40' name='description'><?php echo $row['description'] ?></textarea> <br><br> <!-- 改为submit类型按钮 --> <input type='submit' value='修改'> </form>
其他注意事项
- 可以根据业务需求给表单字段加验证规则,比如季数字段限制只能输入数字
- 生产环境建议隐藏错误详情,避免泄露数据库敏感信息
内容的提问来源于stack exchange,提问作者Mauro
相关产品推荐
相关产品推荐

