Ajax请求后PHP中Mysqli查询无法正常运行问题求助
Hey Edoardo, let's break down the issues in your code and figure out why the query isn't working via Ajax.
1. Incorrect Check for SELECT Query Success
Your condition if ($conn->query($sqlselect) === TRUE) is wrong. For SELECT statements, query() returns a mysqli_result object when successful, not the boolean TRUE (that's only for write operations like INSERT/UPDATE). So this condition will never be true, and all the code inside the block won't run at all.
2. SQL Injection Vulnerability
You're directly concatenating user input variables into your SQL string, which is a huge security risk. Attackers can easily manipulate these values to execute malicious SQL commands. Always use prepared statements instead.
3. Redundant Query Execution
You're running $conn->query($sqlselect) twice—once for the check, once to get the result. This is unnecessary and wastes database resources.
Here's how to rewrite your code to fix these issues, plus proper error handling:
// Assume $conn is your valid mysqli connection $nome = $_POST['nome']; // Or wherever you're getting these values $cognome = $_POST['cognome']; $time = $_POST['time']; $idsede = $_POST['idsede']; $idref = $_POST['idref']; // Ensure these variables are properly initialized $idrep = $_POST['idrep']; // Use prepared statement to prevent SQL injection $sqlselect = "SELECT visitatori_id FROM visitatori WHERE visitatori_nome=? AND visitatori_cognome=? AND visitatori_orastart=? AND visitatori_idsede=?"; $stmt = $conn->prepare($sqlselect); // Bind parameters: s = string, i = integer (adjust types based on your column data types) $stmt->bind_param("sssi", $nome, $cognome, $time, $idsede); $stmt->execute(); $resultz = $stmt->get_result(); // Check if a matching row was found if ($resultz->num_rows > 0) { $rowz = $resultz->fetch_assoc(); $id = $rowz["visitatori_id"]; $data = date('dmY'); $arr = $id."/".$data.$idref.$idrep.$idsede; $JSON = new stdClass(); // Initialize the JSON object properly $JSON->value = $arr; // Return valid JSON response header('Content-Type: application/json'); echo json_encode($JSON); } else { // Handle case where no matching visitor exists header('Content-Type: application/json'); echo json_encode(['error' => 'No visitor found matching the provided criteria']); } // Clean up resources $stmt->close(); $conn->close();
Even with fixed PHP code, your Ajax request might fail for other reasons:
- Verify variable values: Add
var_dump($nome, $cognome, $time, $idsede); exit;at the top of your PHP script to confirm you're receiving the correct values from the Ajax request. - Enable PHP error reporting: Temporarily add
error_reporting(E_ALL); ini_set('display_errors', 1);to the top of your PHP file—this will reveal any syntax or runtime errors breaking the script. - Inspect request in browser dev tools: Go to the Network tab, find your Ajax request, and check:
- If the correct parameters are being sent via POST/GET
- The response status code (200 = success, 404 = wrong PHP file path, 500 = server-side error)
- The raw response content to see if your JSON is properly formatted or if there's an error message from PHP
内容的提问来源于stack exchange,提问作者Edoardo

