在Drupal中用jQuery创建手动保存特定节点的按钮(不调用外部PHP)
Nice one! Since you’re working with Drupal (I can tell from node_load() and node_save()) and want to avoid external PHP files while keeping things secure, here’s a solid approach using jQuery alongside Drupal’s built-in security tools to handle that manual node save button:
Step 1: Update Your Form with Security & AJAX Support
First, we’ll tweak your existing form to include a Drupal CSRF token (critical for security) and structure it for jQuery handling:
<form action="" id="save-node-form" method="POST"> <?php print drupal_get_form_token('save_node_115'); ?> <input type="hidden" name="save_node" value="1"> <button type="submit" id="edit-actionupdatedatebijan" class="form-submit">SAVE NODE</button> </form>
- The
drupal_get_form_token()generates a unique security token tied to this specific node save action, preventing CSRF attacks. - The hidden
save_nodefield lets our backend know this is a node save request.
Step 2: Add jQuery to Handle AJAX Submission
Use jQuery to intercept the form submit, send the request to the current page (no external files!), and handle the response:
jQuery(document).ready(function($) { $('#save-node-form').submit(function(e) { e.preventDefault(); // Stop the default page reload // Serialize all form data (including the security token) var formData = $(this).serialize(); $.ajax({ url: window.location.href, // Submit to the current page type: 'POST', data: formData, dataType: 'json', success: function(response) { if (response.status === 'success') { // Show success message - customize this to fit your site alert(response.message); // Or display in a Drupal-style message area: // $('#messages').html('<div class="status">' + response.message + '</div>'); } else { alert('Error: ' + response.message); } }, error: function() { alert('Oops, something went wrong saving the node.'); } }); }); });
Step 3: Backend PHP Handling (On the Same Page)
Add this PHP code at the top of your page template or custom module page callback to process the request:
<?php if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['save_node']) && isset($_POST['form_token'])) { // Validate the CSRF token to ensure the request is legitimate if (drupal_valid_token($_POST['form_token'], 'save_node_115')) { // Load and save your node $node = node_load(115); // Optional: Modify node fields here if needed // $node->title = 'Updated Node Title'; // $node->field_custom_field['und'][0]['value'] = 'New field value'; node_save($node); // Return appropriate response based on request type if (!empty($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) === 'xmlhttprequest') { // AJAX request: send JSON success response drupal_json_output(array('status' => 'success', 'message' => 'Node saved successfully!')); exit; } else { // Non-AJAX request: show Drupal message and reload drupal_set_message('Node saved successfully!'); drupal_goto(current_path()); } } else { // Invalid token - return error if (!empty($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) === 'xmlhttprequest') { drupal_json_output(array('status' => 'error', 'message' => 'Invalid security token. Please try again.')); exit; } else { drupal_set_message('Invalid security token. Please try again.', 'error'); drupal_goto(current_path()); } } } ?>
Key Security & Functionality Notes
- CSRF Protection: The token validation ensures only legitimate requests from your site can trigger the node save, which is non-negotiable for security.
- No External Files: All processing happens on the current page, so you don’t need to create separate PHP endpoints.
- Flexibility: If you need to modify the node before saving, just add your field updates between
node_load()andnode_save(). - User Feedback: The AJAX response gives clear success/error messages to the user without page reloads.
内容的提问来源于stack exchange,提问作者Zandb
相关产品推荐
相关产品推荐

