You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP代码问题:MySQL余额扣除时无余额不足错误提示

Hey there! Let's break down why your code isn't showing the "Credit not enough" message and fix it step by step:

核心问题分析

Your code has three key issues that are blocking the error message from appearing:

1. 用户名变量错误 + SQL语法问题

You’ve hardcoded $username = 'username'; instead of pulling the logged-in user’s username from the session. Plus, in your SQL query, you wrapped the variable value in backticks (`) — backticks are only for identifying table/column names, not string values. This means your UPDATE is trying to modify a user where the username column equals the literal string username, not the actual logged-in user.

2. 未检查UPDATE是否实际生效

When you run mysql_query($sql, $db);, you don’t verify if any rows were actually updated. If the user’s credit is less than 20, the Credit >=20 condition fails, so no rows are modified — but your code has no way of detecting this.

3. 无条件跳转成功页面

No matter the outcome (success or insufficient credit), you immediately redirect to League.php. So even if the update fails, the user never gets to see your error message.

修正后的代码

Here’s the fixed version of your code that properly handles the insufficient credit case:

<?php
if (session_id() == "") { session_start(); }
if (!isset($_SESSION['username'])) {
    $accessdenied_page = ''; // Make sure this points to your actual access denied page
    header('Location: '.$accessdenied_page);
    exit;
}

$mysql_server = 'localhost';
$mysql_username = '*******';
$mysql_password = '******';
$mysql_database = '******';
$mysql_table = 'details2';
$success_page = 'League.php';
// Pull the logged-in username from the session instead of hardcoding
$username = $_SESSION['username'];

$db = mysql_connect($mysql_server, $mysql_username, $mysql_password);
if (!$db) {
    die('Failed to connect to database server!<br>'.mysql_error());
}
mysql_select_db($mysql_database, $db) or die('Failed to select database<br>'.mysql_error());

// Fix SQL syntax: use single quotes for the username value, not backticks
$sql = "UPDATE `".$mysql_table."` SET `Credit` = `Credit` - 20 WHERE `username` = '".$username."' AND `Credit` >= 20";
mysql_query($sql, $db);

// Check how many rows were affected by the UPDATE
if (mysql_affected_rows($db) == 0) {
    // No rows updated = either the user doesn't exist OR credit is insufficient
    echo "Your Credit is not Enough , Please Buy a Credit";
    // Optional: redirect to a credit purchase page after a delay
    // header("Refresh: 3; url=your_credit_purchase_page.php");
} else {
    // Update successful, redirect to the success page
    header('Location: '.$success_page);
}
exit;
?>
重要额外建议

The mysql_* functions you’re using are deprecated and removed in PHP 7+. For security and long-term compatibility, you should switch to either:

  • MySQLi (improved MySQL extension, supports both procedural and object-oriented syntax)
  • PDO (PHP Data Objects, works with multiple database types)

Both support prepared statements, which will protect your code from SQL injection (your current code is vulnerable because you’re directly inserting a user-provided variable into the query).

内容的提问来源于stack exchange,提问作者Jeyson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:51:38