You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在FPDF的write()方法中正确输出MySQL查询结果内容?

Fixing the FPDF Write() Issue & SQL Injection Risk

Alright, let's tackle this problem step by step. The core issue here is that you're trying to use echo inside the Write() method call—and that doesn't work the way you think it does.

Why the original code fails

echo is a PHP construct that outputs content directly to the browser's HTTP response. But FPDF's Write() method expects a complete string as its second parameter to write into the PDF document. Your current code is just passing a string that includes the literal text "echo $row["student_name"];" instead of inserting the actual value from your database.

The correct way to insert database values into the PDF text

You have two clean options to embed the $row values into your string:

1. String concatenation (using the . operator)

This is straightforward—you just piece together static text and your database values:

$pdf->Write(6, 'I, ' . $row["student_name"] . ', of legal age and a resident of ' . $row["present_address"] . ' understand that an Educational Scholarship/Financial Grants-in Aid has been awarded to me so that I may enroll in and complete the ' . $row["course"] . '.');

2. Double-quoted string interpolation (cleaner syntax)

PHP allows you to directly embed variables inside double-quoted strings. For array elements, wrap them in curly braces to avoid parsing ambiguity:

$pdf->Write(6, "I, {$row['student_name']}, of legal age and a resident of {$row['present_address']} understand that an Educational Scholarship/Financial Grants-in Aid has been awarded to me so that I may enroll in and complete the {$row['course']}.");

Critical bonus fix: Prevent SQL Injection

Your original code has a huge security hole—you're directly inserting $_GET['id'] into your SQL query, which leaves you wide open to SQL injection attacks. Let's fix that with prepared statements:

$con = mysqli_connect("localhost","root","","final_osa");

// Use a prepared statement instead of directly concatenating $_GET['id']
$sel_query = "SELECT * FROM ched_scholars WHERE id = ?;";
$stmt = mysqli_prepare($con, $sel_query);
// "i" means we're passing an integer (adjust to "s" if id is a string)
mysqli_stmt_bind_param($stmt, "i", $_GET['id']);
mysqli_stmt_execute($stmt);
$result = mysqli_stmt_get_result($stmt);

while($row = mysqli_fetch_assoc($result)) {
    // Use either concatenation or interpolation here
    $pdf->Write(6, "I, {$row['student_name']}, of legal age and a resident of {$row['present_address']} understand that an Educational Scholarship/Financial Grants-in Aid has been awarded to me so that I may enroll in and complete the {$row['course']}.");
}

Prepared statements separate your SQL logic from user input, eliminating the risk of injection.

内容的提问来源于stack exchange,提问作者1437

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:53:06