如何用submit类型input替代a标签传参实现待售皮肤入库?
Hey there! Let's get this sorted out—you want to swap that anchor tag for a submit input that sends skin data to your backend to insert into the database, right? Here's a straightforward, secure way to do it:
Key Changes Needed:
- Wrap each skin entry in a
<form>(submit inputs rely on forms to send data to the server) - Use hidden inputs to pass the weapon/skin details (instead of putting them in the URL)
- Style the submit button to match your original link's appearance
Modified Frontend Code
Replace your existing echo statement with this:
echo '<td> <form method="POST" action="wystaw.php"> <!-- Hidden inputs to pass skin data securely --> <input type="hidden" name="weapon" value="' . htmlspecialchars($key['weapon']) . '"> <input type="hidden" name="skin" value="' . htmlspecialchars($key['skin']) . '"> <!-- Submit button styled like your original anchor tag --> <input type="submit" class="btn btn-primary" value="Wystaw"> </form> </td>';
Note: We use htmlspecialchars() to escape the values, which prevents XSS attacks and ensures proper HTML rendering.
Backend (wystaw.php) Database Insertion Code
Now update wystaw.php to receive the POST data and insert it into your database. Here's a secure example using prepared statements (the safest way to prevent SQL injection):
<?php // Replace with your actual database credentials $servername = "your_db_server"; $username = "your_db_user"; $password = "your_db_pass"; $dbname = "your_db_name"; // Establish database connection $conn = new mysqli($servername, $username, $password, $dbname); if ($conn->connect_error) { die("Connection failed: " . $conn->connect_error); } // Use prepared statement to insert data $stmt = $conn->prepare("INSERT INTO your_skin_table (weapon, skin) VALUES (?, ?)"); $stmt->bind_param("ss", $weapon, $skin); // Assign values from the submitted form $weapon = $_POST['weapon']; $skin = $_POST['skin']; // Execute the insertion if ($stmt->execute()) { echo "Skin listed successfully!"; // Optional: Redirect back to your listings page // header("Location: your_listings_page.php"); // exit(); } else { echo "Error: " . $stmt->error; } // Clean up connections $stmt->close(); $conn->close(); ?>
Don't forget to replace your_skin_table with the actual name of your database table where skin listings are stored.
内容的提问来源于stack exchange,提问作者Season6

