报价表单提交时页面刷新问题求助(附PHP代码)
Fixing Your Quotation Form PHP Handler
Hey James, I see exactly where the issues are with your PHP form processing code—let's walk through each problem and fix them so your form submits properly without just refreshing:
Key Problems in Your Current Code
- Mismatched Variable Names: Your validation checks use variables like
$first_name,$email_address, and$commentswhich don't match the actual variable names you defined ($senderFirst,$senderEmail,$issue_discription). This means your validation logic is failing immediately, causing unexpected redirects or refreshes. - Broken Message Concatenation: The car details and image upload fields aren't being added to your
$msgvariable—you're just writing standalone strings instead of appending them to the message. - Incorrect File Upload Handling: You can't retrieve uploaded files with
$_REQUEST; you need to use the$_FILESsuperglobal, and you're not handling the actual file upload process at all. - Missing
exit()After Redirects: When usingheader()to redirect, you need to addexit();right after to stop the rest of the script from running, which can cause unexpected behavior. - Incomplete Validation: Your current validation only checks a couple of fields, and doesn't verify email format or other critical inputs.
Corrected PHP Code
<?php // Set your target email $webmaster_email = "jhugill94@gmail.com"; // Page URLs $feedback_page = "/Quotation.html"; $error_page = "/error_message.html"; $thankyou_page = "/thank_you.html"; // Sanitize and retrieve form data $senderFirst = trim($_POST['senderFirst'] ?? ''); $senderLast = trim($_POST['senderLast'] ?? ''); $senderNumber = trim($_POST['senderNumber'] ?? ''); $senderEmail = trim($_POST['senderEmail'] ?? ''); $issue_discription = trim($_POST['issue_discription'] ?? ''); $car_make = trim($_POST['car_make'] ?? ''); $car_model = trim($_POST['car_model'] ?? ''); $fuel_type = trim($_POST['fuel_type'] ?? ''); $engine_size = trim($_POST['engine_size'] ?? ''); // Handle file upload (if needed) $image_upload_info = ''; if (!empty($_FILES['image_upload']['tmp_name']) && $_FILES['image_upload']['error'] === UPLOAD_ERR_OK) { $upload_dir = 'uploads/'; // Create this folder and set proper permissions (755) $filename = basename($_FILES['image_upload']['name']); $target_path = $upload_dir . uniqid() . '_' . $filename; if (move_uploaded_file($_FILES['image_upload']['tmp_name'], $target_path)) { $image_upload_info = "Uploaded Image: " . $target_path . "\r\n"; } else { $image_upload_info = "Image upload failed\r\n"; } } // Build the complete message $msg = "First Name: " . $senderFirst . "\r\n" . "Surname: " . $senderLast . "\r\n" . "Contact Number: " . $senderNumber . "\r\n" . "Email: " . $senderEmail . "\r\n" . "Issue Description: " . $issue_discription . "\r\n" . "Car Make: " . $car_make . "\r\n" . "Car Model: " . $car_model . "\r\n" . "Fuel Type: " . $fuel_type . "\r\n" . "Engine Size: " . $engine_size . "\r\n" . $image_upload_info; // Email injection check function function isInjected($str) { $injections = array('(\n+)', '(\r+)', '(\t+)', '(%0A+)', '(%0D+)', '(%08+)', '(%09+)' ); $inject = join('|', $injections); $inject = "/$inject/i"; return preg_match($inject, $str); } // Validation logic if (!isset($_POST['senderEmail'])) { // Redirect if accessed directly header("Location: $feedback_page"); exit(); } elseif (empty($senderFirst) || empty($senderEmail) || empty($senderNumber)) { // Check required fields header("Location: $error_page"); exit(); } elseif (!filter_var($senderEmail, FILTER_VALIDATE_EMAIL)) { // Validate email format header("Location: $error_page"); exit(); } elseif (isInjected($senderEmail) || isInjected($senderFirst) || isInjected($issue_discription)) { // Check for email injection header("Location: $error_page"); exit(); } else { // Send the email $headers = "From: $senderEmail\r\nReply-To: $senderEmail"; if (mail($webmaster_email, "Quotation Request", $msg, $headers)) { header("Location: $thankyou_page"); } else { // If email fails to send, redirect to error page header("Location: $error_page"); } exit(); } ?>
Additional Notes
- Make sure your HTML form uses
method="POST"and hasenctype="multipart/form-data"to handle file uploads. - Create an
uploadsdirectory in the same folder as your PHP script, and set its permissions to 755 so the server can write files to it. - You might want to add more validation for phone numbers, car details, etc., depending on your needs.
- Always sanitize user input to prevent security issues—using
trim()is a start, but you could also usehtmlspecialchars()if needed.
内容的提问来源于stack exchange,提问作者James Miller
相关产品推荐
相关产品推荐

