员工请假系统问题:如何按登录用户展示个人请假记录
Let's get this sorted out quickly! The core issue right now is that your leave query is pulling all records from the leaves table without filtering for the logged-in user. You already have the logged-in user's ID stored in $user_id from your session code—we just need to connect that to your leave fetch logic.
Step 1: Confirm the Link Between employee and leaves Tables
First, make sure your leaves table has a column that references the id column from the employee table. Common names for this are employee_id or user_id. I'll assume it's employee_id for this example—adjust it to match your actual column name if needed.
Step 2: Integrate Session Data with the Leave Query
You already have the $user_id variable available from your session code. We'll modify your PDO query to only fetch leaves where the associated employee ID matches $user_id, and use parameter binding to keep the query secure.
Full Integrated Code
Here's how to combine your session logic and leave view code properly:
<?php session_start(); ob_start(); // Include the database connection file (use your existing database_connection.php or database.php, whichever is correct) include "database_connection.php"; // Check valid session if(isset($_SESSION["VALID_USER_ID"])) { $check_user_details = mysql_query("select * from `employee` where `username` = '".mysql_real_escape_string($_SESSION["VALID_USER_ID"])."'"); if(mysql_num_rows($check_user_details) < 1) { session_unset(); session_destroy(); header("location: login.php"); exit; // Add exit to stop further execution after redirect } else { $get_user_details = mysql_fetch_array($check_user_details); $user_id = strip_tags($get_user_details['id']); // ... (you can keep all the other user variables here if you need them) ?> <div class="container"> <div class="page-header"> <h3>My Leaves</h3> <div class="table-responsive"> <table class="table"> <tr> <th>Employee Name</th> <th>Phone</th> <th>Email</th> <th>From</th> <th>To</th> <th>Reason</th> <th>Status</th> </tr> <?php // Use your database connection (note: if database.php uses PDO, make sure $database is available here) // Modify the query to filter by the logged-in user's ID $result = $database->prepare("SELECT * FROM leaves WHERE employee_id = :user_id ORDER BY leaveno DESC"); // Bind the user ID parameter to avoid SQL injection $result->bindParam(':user_id', $user_id, PDO::PARAM_INT); $result->execute(); while($row_message = $result->fetch()){ // Use while instead of for for cleaner iteration ?> <tr> <td><?php echo htmlspecialchars($row_message['full_name']); ?></td> <td><?php echo htmlspecialchars($row_message['phone']); ?></td> <td><?php echo htmlspecialchars($row_message['email']); ?></td> <td><?php echo htmlspecialchars($row_message['fromdate']); ?></td> <td><?php echo htmlspecialchars($row_message['todate']); ?></td> <td><?php echo htmlspecialchars($row_message['reason']); ?></td> <td><?php echo htmlspecialchars($row_message['status']); ?></td> </tr> <?php } ?> </table> <a href="home"><button type="button" class="btn btn-primary"><i class="glyphicon glyphicon-arrow-left"></i> Back</button></a> </div> </div> </div> <?php } } else { // Redirect to login if no valid session header("location: login.php"); exit; } ?>
Key Changes Made:
- Added a
WHERE employee_id = :user_idclause to the leave query to filter for the current user - Used PDO parameter binding (
bindParam) to safely pass the$user_idvalue to the query (prevents SQL injection) - Replaced the
forloop with awhileloop for more natural iteration over query results - Added
htmlspecialchars()around echoed values to prevent XSS vulnerabilities (a good practice!) - Added
exitafter redirects to stop further script execution
Quick Notes:
- If your
leavestable uses a different column name for the employee ID (likeuser_idinstead ofemployee_id), update that in the WHERE clause. - You mentioned knowing
mysql_*functions are deprecated—once you fix this immediate issue, migrating your session code to PDO (matching your leave query code) will make the whole system more secure and maintainable.
内容的提问来源于stack exchange,提问作者user9236271

