PHP与MySQL中Undefined index: cid错误排查求助
Hey there! Let's break down why you're hitting that Notice: Undefined index: cid error and get your comment edit system working properly.
What's Causing the Error?
That notice pops up because your editcomments.php script tries to access $_POST['cid'] on line 19, but that value never makes it to the script. There are two key issues here:
- Broken HTML in your comment form: The hidden input fields in
environment.inc.phphave unclosed quotes for theirvalueattributes. This messes up how the browser renders the form, so thecidvalue never gets sent when you click "Edit". - No check for valid POST data: If you (or anyone) visits
editcomments.phpdirectly without submitting the edit form, there's no POST data at all—so trying to access$_POST['cid']throws the error.
Step 1: Fix the Form in environment.inc.php
Look at the form inside your getComments function—you forgot to close the single quotes on most value attributes. Here's the corrected version (I also fixed a mismatched closing tag):
function getComments($conn) { $sql = "SELECT * FROM environments"; $result = mysqli_query($conn, $sql); while($row = $result->fetch_assoc() ) { echo "<div><p>"; echo $row['uid']."<br>"; echo $row['date']."<br>"; echo nl2br($row['message']); echo "</p> <form method='POST' action='editcomments.php'> <input type='hidden' name='cid' value='".$row['cid']."'> <input type='hidden' name='uid' value='".$row['uid']."'> <input type='hidden' name='date' value='".$row['date']."'> <input type='hidden' name='message' value='".$row['message']."'> <button>Edit</button> </form> </div>"; } }
Step 2: Fix editcomments.php to Validate POST Data
You need to first confirm the required POST parameters exist before using them. I also added the cid hidden input back to the edit form (you'll need it to update the correct comment later) and fixed unclosed quotes here too:
<?php date_default_timezone_set("America/New_York"); include'dbh.inc.php'; include'environment.inc.php'; ?> <!DOCTYPE html> <html lang=""> <head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>Edit Comment</title> <link rel="stylesheet" type="text/css" href="style.css"> </head> <body> <?php // Check that all required POST data exists before proceeding if(isset($_POST['cid'], $_POST['uid'], $_POST['date'], $_POST['message'])) { $cid = $_POST['cid']; $uid = $_POST['uid']; $date = $_POST['date']; $message = $_POST['message']; // Render the fixed edit form with all necessary hidden inputs echo "<form method='POST' action='editcomments.php'> <input type='hidden' name='cid' value='".$cid."'> <input type='hidden' name='uid' value='".$uid."'> <input type='hidden' name='date' value='".$date."'> <textarea name='message'>".$message."</textarea> <button type='submit' name='commentSubmit'>Edit</button> </form>"; } else { // Show a friendly message if someone visits the page directly echo "<p>Oops! You can't access this page directly. Please go back and click the Edit button on a comment.</p>"; } ?> </body> </html>
Quick Safety Tip for New Developers
Since you're just starting out, I should mention: your current code is vulnerable to SQL injection because you're directly inserting user input into SQL queries. Once you fix this error, look into using prepared statements with mysqli_prepare() and mysqli_stmt_bind_param() to keep your database safe from attacks.
内容的提问来源于stack exchange,提问作者Reha Mathur

