mysqli_stmt_num_rows持续返回0问题及PHP表单代码求助
Hey there! Let's break down your problems step by step—first figuring out why mysqli_stmt_num_rows keeps returning 0, then fixing up your form validation code.
mysqli_stmt_num_rows Might Be Returning 0 This is a super common pitfall with MySQLi prepared statements. Here are the most likely causes:
You didn't store the result set first
Unlike regularmysqli_num_rows(), the statement version requires you to explicitly store the result on the client side before you can count rows. If you skip this, it'll always return 0. Add this line right after executing your statement:mysqli_stmt_execute($stmt); // Critical step: Store the result to access row counts mysqli_stmt_store_result($stmt); $rowCount = mysqli_stmt_num_rows($stmt); // Now this works!Your query actually returns no matching rows
Double-check that your SQL logic is correct. Take the exact query you're using in your prepared statement, replace the placeholders with real values (the ones you're binding), and run it directly in your database tool (like phpMyAdmin or MySQL CLI). If it returns nothing, that's why the function gives 0.There's an error in your statement or connection
Always check for errors after preparing, binding, or executing a statement. A hidden error could mean your query never ran properly. Add error checks like this:$stmt = mysqli_prepare($conn, "SELECT * FROM your_table WHERE column = ?"); if (!$stmt) { die("Prepare failed: " . mysqli_error($conn)); } mysqli_stmt_bind_param($stmt, "s", $yourVariable); mysqli_stmt_execute($stmt); if (mysqli_stmt_errno($stmt)) { die("Execute failed: " . mysqli_stmt_error($stmt)); }Incorrect parameter binding
Make sure the data type you're binding matches the database column type. For example, using"i"(integer) for a string column will cause the query to look for integer matches that don't exist, resulting in 0 rows.
Looking at your snippet, here are the clear problems and fixes:
Unfinished variable assignment
You left$reviewOK = tru...hanging—this will throw a syntax error. Fix it to$reviewOK = true;.Undefined variables risk
Variables like$nameOKand$reviewOKaren't initialized at the top. If a user submits the form without triggering certain branches, these variables will be undefined later when you check them. Initialize them at the start:$nameOK = $reviewOK = false; $nameErr = $reviewErr = "";Missing input cleaning
You're directly using$_POSTvalues without trimming whitespace or sanitizing. This can lead to empty submissions that slip through, or XSS risks if you output the data later. Addtrim()andhtmlspecialchars():$name = trim($_POST['name']); $review = htmlspecialchars(trim($_POST['review']));No final validation check
You're validating each field individually, but there's no logic to trigger your database action only when all fields pass. Add a check at the end of theisset($_POST['submit'])block:if ($nameOK && $reviewOK) { // Here's where you run your prepared statement to insert the review }
Fixed Code Snippet
Here's how your cleaned-up validation might look:
<?php $nameErr = $reviewErr = ""; $nameOK = $reviewOK = false; $name = $review = ""; if (isset($_POST['submit'])) { // 姓名验证 if (isset($_POST['anoniem'])) { $name = "匿名"; $nameOK = true; } else if (empty(trim($_POST['name']))) { $nameErr = "请输入您的姓名或勾选‘匿名’选项。"; } else { $name = trim($_POST['name']); $nameOK = true; } // 评论验证 if (empty(trim($_POST['review']))) { $reviewErr = "请输入您的评论"; } else if (preg_match("/(kut|fuck|fucking)/i", trim($_POST['review']))) { $reviewErr = "请不要在评论中使用脏话"; } else { $review = htmlspecialchars(trim($_POST['review'])); $reviewOK = true; } // 所有验证通过后处理数据 if ($nameOK && $reviewOK) { // 执行数据库插入等操作(记得用预处理语句!) } } ?>
内容的提问来源于stack exchange,提问作者Djordy Koert

