You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PHP和MySQL更新信息遇问题,请求排查$_POST相关错误

Fixing Your PHP/MySQL Update Issue (Focus on $_POST & Security)

Hey there! As someone new to PHP, it's totally normal to hit snags like this. Let's walk through the problems in your code and get your update functionality working safely and correctly.

First, Let's Identify the Key Issues

  • Outdated MySQL Extension: You're using mysql_query() and related functions — this extension has been completely removed from modern PHP versions. You'll need to switch to either mysqli (MySQL Improved) or PDO; we'll use mysqli here since it's closest to your original code.
  • Critical SQL Injection Risk: Directly inserting $_POST values into your SQL query is a huge security hole. Attackers could manipulate this to steal or delete your database data.
  • Potential $_POST Misconfiguration: If your form isn't set up correctly (wrong method, mismatched name attributes), $_POST['submit'] or $_POST['medicalin'] won't be populated.
  • Incomplete Code & Error Handling: Your success script is cut off (echo"<script>window....";), and you don't have error checking for the database query, which makes it hard to debug.

Step-by-Step Fixed Code

First, let's assume your config.php connects to the database using mysqli (if it still uses mysql_connect(), update that too!). Here's the revised update logic:

<?php
include("config.php");

// Make sure $user['id'] is properly set (e.g., from a logged-in session)
session_start(); // If you're using sessions for user auth
if (!isset($user['id'])) {
    echo "<script>alert('User not logged in!'); window.location.href='login.php';</script>";
    exit();
}

if (isset($_POST['submit'])) {
    // Sanitize and validate input
    $medical = trim($_POST['medicalin']);
    if (empty($medical)) {
        echo "<script>alert('Please enter some Medical Information, if there is none to report, simply type N/A.');</script>";
        exit();
    }

    // Use prepared statements to prevent SQL injection
    $query = "UPDATE test SET medical = ? WHERE id = ?";
    $stmt = mysqli_prepare($conn, $query);
    mysqli_stmt_bind_param($stmt, "si", $medical, $user['id']); // "s" = string, "i" = integer

    if (mysqli_stmt_execute($stmt)) {
        echo "<script>alert('Medical information updated successfully!'); window.location.href='dashboard.php';</script>";
    } else {
        // Debug the error if something goes wrong
        echo "<script>alert('Update failed: " . mysqli_error($conn) . "');</script>";
    }

    mysqli_stmt_close($stmt);
}
?>

Important Checks for $_POST

Make sure your HTML form looks like this (the name attributes must match what you're using in $_POST):

<form method="POST" action="your-update-page.php">
    <label for="medicalin">Medical Information:</label>
    <input type="text" id="medicalin" name="medicalin" required>
    <button type="submit" name="submit">Update Information</button>
</form>
  • Confirm the form uses method="POST" (not GET).
  • Double-check that the input field has name="medicalin" (the id is just for labels, the name is what PHP uses for $_POST).
  • The submit button must have name="submit" so isset($_POST['submit']) works.

Additional Tips

  • Always validate and sanitize user input (we used trim() here, but you can add more checks if needed).
  • Enable PHP error reporting during development to catch issues: error_reporting(E_ALL); ini_set('display_errors', 1);
  • Store user sessions securely if you're relying on $user['id'] (make sure session_start() is at the top of every page that uses sessions).

内容的提问来源于stack exchange,提问作者WPS Team

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:13:32