PHP代码问题:MySQL余额扣除时无余额不足错误提示
Hey there! Let's break down why your code isn't showing the "Credit not enough" message and fix it step by step:
Your code has three key issues that are blocking the error message from appearing:
1. 用户名变量错误 + SQL语法问题
You’ve hardcoded $username = 'username'; instead of pulling the logged-in user’s username from the session. Plus, in your SQL query, you wrapped the variable value in backticks (`) — backticks are only for identifying table/column names, not string values. This means your UPDATE is trying to modify a user where the username column equals the literal string username, not the actual logged-in user.
2. 未检查UPDATE是否实际生效
When you run mysql_query($sql, $db);, you don’t verify if any rows were actually updated. If the user’s credit is less than 20, the Credit >=20 condition fails, so no rows are modified — but your code has no way of detecting this.
3. 无条件跳转成功页面
No matter the outcome (success or insufficient credit), you immediately redirect to League.php. So even if the update fails, the user never gets to see your error message.
Here’s the fixed version of your code that properly handles the insufficient credit case:
<?php if (session_id() == "") { session_start(); } if (!isset($_SESSION['username'])) { $accessdenied_page = ''; // Make sure this points to your actual access denied page header('Location: '.$accessdenied_page); exit; } $mysql_server = 'localhost'; $mysql_username = '*******'; $mysql_password = '******'; $mysql_database = '******'; $mysql_table = 'details2'; $success_page = 'League.php'; // Pull the logged-in username from the session instead of hardcoding $username = $_SESSION['username']; $db = mysql_connect($mysql_server, $mysql_username, $mysql_password); if (!$db) { die('Failed to connect to database server!<br>'.mysql_error()); } mysql_select_db($mysql_database, $db) or die('Failed to select database<br>'.mysql_error()); // Fix SQL syntax: use single quotes for the username value, not backticks $sql = "UPDATE `".$mysql_table."` SET `Credit` = `Credit` - 20 WHERE `username` = '".$username."' AND `Credit` >= 20"; mysql_query($sql, $db); // Check how many rows were affected by the UPDATE if (mysql_affected_rows($db) == 0) { // No rows updated = either the user doesn't exist OR credit is insufficient echo "Your Credit is not Enough , Please Buy a Credit"; // Optional: redirect to a credit purchase page after a delay // header("Refresh: 3; url=your_credit_purchase_page.php"); } else { // Update successful, redirect to the success page header('Location: '.$success_page); } exit; ?>
The mysql_* functions you’re using are deprecated and removed in PHP 7+. For security and long-term compatibility, you should switch to either:
- MySQLi (improved MySQL extension, supports both procedural and object-oriented syntax)
- PDO (PHP Data Objects, works with multiple database types)
Both support prepared statements, which will protect your code from SQL injection (your current code is vulnerable because you’re directly inserting a user-provided variable into the query).
内容的提问来源于stack exchange,提问作者Jeyson

