使用PHP和MySQL更新信息遇问题,请求排查$_POST相关错误
Fixing Your PHP/MySQL Update Issue (Focus on $_POST & Security)
Hey there! As someone new to PHP, it's totally normal to hit snags like this. Let's walk through the problems in your code and get your update functionality working safely and correctly.
First, Let's Identify the Key Issues
- Outdated MySQL Extension: You're using
mysql_query()and related functions — this extension has been completely removed from modern PHP versions. You'll need to switch to eithermysqli(MySQL Improved) or PDO; we'll use mysqli here since it's closest to your original code. - Critical SQL Injection Risk: Directly inserting
$_POSTvalues into your SQL query is a huge security hole. Attackers could manipulate this to steal or delete your database data. - Potential $_POST Misconfiguration: If your form isn't set up correctly (wrong method, mismatched
nameattributes),$_POST['submit']or$_POST['medicalin']won't be populated. - Incomplete Code & Error Handling: Your success script is cut off (
echo"<script>window....";), and you don't have error checking for the database query, which makes it hard to debug.
Step-by-Step Fixed Code
First, let's assume your config.php connects to the database using mysqli (if it still uses mysql_connect(), update that too!). Here's the revised update logic:
<?php include("config.php"); // Make sure $user['id'] is properly set (e.g., from a logged-in session) session_start(); // If you're using sessions for user auth if (!isset($user['id'])) { echo "<script>alert('User not logged in!'); window.location.href='login.php';</script>"; exit(); } if (isset($_POST['submit'])) { // Sanitize and validate input $medical = trim($_POST['medicalin']); if (empty($medical)) { echo "<script>alert('Please enter some Medical Information, if there is none to report, simply type N/A.');</script>"; exit(); } // Use prepared statements to prevent SQL injection $query = "UPDATE test SET medical = ? WHERE id = ?"; $stmt = mysqli_prepare($conn, $query); mysqli_stmt_bind_param($stmt, "si", $medical, $user['id']); // "s" = string, "i" = integer if (mysqli_stmt_execute($stmt)) { echo "<script>alert('Medical information updated successfully!'); window.location.href='dashboard.php';</script>"; } else { // Debug the error if something goes wrong echo "<script>alert('Update failed: " . mysqli_error($conn) . "');</script>"; } mysqli_stmt_close($stmt); } ?>
Important Checks for $_POST
Make sure your HTML form looks like this (the name attributes must match what you're using in $_POST):
<form method="POST" action="your-update-page.php"> <label for="medicalin">Medical Information:</label> <input type="text" id="medicalin" name="medicalin" required> <button type="submit" name="submit">Update Information</button> </form>
- Confirm the form uses
method="POST"(not GET). - Double-check that the input field has
name="medicalin"(theidis just for labels, thenameis what PHP uses for$_POST). - The submit button must have
name="submit"soisset($_POST['submit'])works.
Additional Tips
- Always validate and sanitize user input (we used
trim()here, but you can add more checks if needed). - Enable PHP error reporting during development to catch issues:
error_reporting(E_ALL); ini_set('display_errors', 1); - Store user sessions securely if you're relying on
$user['id'](make suresession_start()is at the top of every page that uses sessions).
内容的提问来源于stack exchange,提问作者WPS Team
相关产品推荐
相关产品推荐

