如何获取用户会话数据插入其他表?会话变量取值为空问题求助
Hey there, the main issue here is how you're accessing your session variables—you've got an extra $ inside the session key strings, which is causing PHP to look for session entries literally named $u_email and $u_uid instead of the correct keys u_email and u_uid. That's why those values are coming up empty!
Let's walk through fixing this, plus adding proper validation and secure database insertion.
Step 1: Correct Session Variable Access
Remove the $ from inside the session array keys. Here's the fixed core code with improved validation:
<?php session_start(); // Check if the form was submitted if(isset($_POST['button'])){ $bidamount = trim($_POST['bidamount']); // Fixed session variable keys (no $ inside quotes) $email = $_SESSION['u_email'] ?? null; $uid = $_SESSION['u_uid'] ?? null; // Validate all required fields and stop execution if missing if(empty($bidamount) || empty($email) || empty($uid)){ echo "Please fill in all required fields."; exit; // Prevent further code execution } // Now proceed with database insertion... } ?>
I added the null coalescing operator (?? null) to avoid "undefined index" notices if the session variables aren't set, expanded the validation to check all required fields (including session data), and used exit to stop submission of incomplete data—fixing your original issue where blank fields still went through.
Step 2: Secure Database Insertion Example
To safely insert this data into another table, always use prepared statements (never concatenate user input directly into SQL queries—this prevents SQL injection attacks). Here's an example using MySQLi:
// Assuming you already have a MySQLi connection established $conn = new mysqli("localhost", "your_username", "your_password", "your_database"); // Check connection if ($conn->connect_error) { die("Connection failed: " . $conn->connect_error); } // Prepare the insert statement (replace table/column names with yours) $stmt = $conn->prepare("INSERT INTO bids (user_id, user_email, bid_amount) VALUES (?, ?, ?)"); // Bind parameters: "isd" = integer (uid), string (email), double (bidamount) $stmt->bind_param("isd", $uid, $email, $bidamount); // Execute and handle result if($stmt->execute()){ echo "Bid submitted successfully!"; } else { echo "Error submitting bid: " . $stmt->error; } // Clean up resources $stmt->close(); $conn->close();
If you prefer PDO, here's the equivalent secure implementation:
// Assuming PDO connection is set up $pdo = new PDO("mysql:host=localhost;dbname=your_database", "your_username", "your_password"); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); // Prepare insert statement $stmt = $pdo->prepare("INSERT INTO bids (user_id, user_email, bid_amount) VALUES (:uid, :email, :bidamount)"); // Bind parameters with explicit types $stmt->bindParam(':uid', $uid, PDO::PARAM_INT); $stmt->bindParam(':email', $email, PDO::PARAM_STR); $stmt->bindParam(':bidamount', $bidamount, PDO::PARAM_STR); // Execute $stmt->execute(); echo "Bid submitted successfully!";
Additional Best Practice: Verify User Login
Add a check at the top of your script to ensure only logged-in users can access the bid form:
session_start(); // Redirect to login if session data is missing if(!isset($_SESSION['u_email']) || !isset($_SESSION['u_uid'])){ header("Location: login.php"); exit; }
This way, unauthenticated users can't even reach the bid submission logic, reducing potential errors.
内容的提问来源于stack exchange,提问作者Ethan Dennis

