You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

员工请假系统问题:如何按登录用户展示个人请假记录

Fix: Show Only Current User's Leave Records

Let's get this sorted out quickly! The core issue right now is that your leave query is pulling all records from the leaves table without filtering for the logged-in user. You already have the logged-in user's ID stored in $user_id from your session code—we just need to connect that to your leave fetch logic.

First, make sure your leaves table has a column that references the id column from the employee table. Common names for this are employee_id or user_id. I'll assume it's employee_id for this example—adjust it to match your actual column name if needed.

Step 2: Integrate Session Data with the Leave Query

You already have the $user_id variable available from your session code. We'll modify your PDO query to only fetch leaves where the associated employee ID matches $user_id, and use parameter binding to keep the query secure.

Full Integrated Code

Here's how to combine your session logic and leave view code properly:

<?php 
session_start(); 
ob_start(); 
// Include the database connection file (use your existing database_connection.php or database.php, whichever is correct)
include "database_connection.php";

// Check valid session
if(isset($_SESSION["VALID_USER_ID"])) {
    $check_user_details = mysql_query("select * from `employee` where `username` = '".mysql_real_escape_string($_SESSION["VALID_USER_ID"])."'");
    if(mysql_num_rows($check_user_details) < 1) {
        session_unset();
        session_destroy();
        header("location: login.php");
        exit; // Add exit to stop further execution after redirect
    } else {
        $get_user_details = mysql_fetch_array($check_user_details);
        $user_id = strip_tags($get_user_details['id']);
        // ... (you can keep all the other user variables here if you need them)
?>

<div class="container">
    <div class="page-header">
        <h3>My Leaves</h3>
        <div class="table-responsive">
            <table class="table">
                <tr>
                    <th>Employee Name</th>
                    <th>Phone</th>
                    <th>Email</th>
                    <th>From</th>
                    <th>To</th>
                    <th>Reason</th>
                    <th>Status</th>
                </tr>
                <?php 
                // Use your database connection (note: if database.php uses PDO, make sure $database is available here)
                // Modify the query to filter by the logged-in user's ID
                $result = $database->prepare("SELECT * FROM leaves WHERE employee_id = :user_id ORDER BY leaveno DESC");
                // Bind the user ID parameter to avoid SQL injection
                $result->bindParam(':user_id', $user_id, PDO::PARAM_INT);
                $result->execute();
                while($row_message = $result->fetch()){ // Use while instead of for for cleaner iteration
                ?>
                <tr>
                    <td><?php echo htmlspecialchars($row_message['full_name']); ?></td>
                    <td><?php echo htmlspecialchars($row_message['phone']); ?></td>
                    <td><?php echo htmlspecialchars($row_message['email']); ?></td>
                    <td><?php echo htmlspecialchars($row_message['fromdate']); ?></td>
                    <td><?php echo htmlspecialchars($row_message['todate']); ?></td>
                    <td><?php echo htmlspecialchars($row_message['reason']); ?></td>
                    <td><?php echo htmlspecialchars($row_message['status']); ?></td>
                </tr>
                <?php } ?>
            </table>
            <a href="home"><button type="button" class="btn btn-primary"><i class="glyphicon glyphicon-arrow-left"></i> Back</button></a>
        </div>
    </div>
</div>

<?php 
    }
} else {
    // Redirect to login if no valid session
    header("location: login.php");
    exit;
}
?>

Key Changes Made:

  • Added a WHERE employee_id = :user_id clause to the leave query to filter for the current user
  • Used PDO parameter binding (bindParam) to safely pass the $user_id value to the query (prevents SQL injection)
  • Replaced the for loop with a while loop for more natural iteration over query results
  • Added htmlspecialchars() around echoed values to prevent XSS vulnerabilities (a good practice!)
  • Added exit after redirects to stop further script execution

Quick Notes:

  • If your leaves table uses a different column name for the employee ID (like user_id instead of employee_id), update that in the WHERE clause.
  • You mentioned knowing mysql_* functions are deprecated—once you fix this immediate issue, migrating your session code to PDO (matching your leave query code) will make the whole system more secure and maintainable.

内容的提问来源于stack exchange,提问作者user9236271

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:47:42