PHP中$_POST取值失败,插入数据库多数字段为空求排查
问题排查:PHP表单POST字段无法获取值的原因及解决办法
我最近写了一个添加产品的PHP表单,表单采用POST方法并设置了enctype="multipart/form-data"。提交表单后,通过$_POST获取字段值时,除了product_featured和product_image外,其余字段均无法正确获取,执行INSERT语句输出结果显示对应字段为空。我已反复检查拼写未发现问题,恳请帮忙排查错误原因。
我的代码:
HTML表单部分:
<!DOCTYPE html > <html> <head> <meta content="text/html; charset=utf-8" http-equiv="Content-Type" /> <title>Untitled 1</title> <script src="https://cloud.tinymce.com/stable/tinymce.min.js"></script> <script>tinymce.init({ selector:'textarea' });</script> </head> <body> <form action="insert_product.php" method="post" enctype="multipart/form-data"> <table> <tr> <td>Name</td> <td><input type="text" name="product_title" required="required"></td> </tr> <tr> <td>category</td> <td><select name="product_category" > <option>Select a Category</option> <?php $get_cats = " select * from categories"; $run_cats = mysqli_query($con, $get_cats); while($row_cats = mysqli_fetch_array($run_cats)) { $cat_id = $row_cats['cat_id']; $cat_title = $row_cats['cat_data']; echo " <option>$cat_title </option> "; } ?> </select></td> </tr> <tr> <td>featured</td> <td><select name="product_featured" > <option>0</option> <option>1</option> </select></td> </tr> <tr> <td>price</td> <td><input type="text" name="product_price" required="required"></td> </tr> <tr> <td>image</td> <td><input type="file" name="product_image" required="required"></td> </tr> <tr> <td>keywords</td> <td><input type="text" name="product_keywords" required="required"></td> </tr> <tr> <td>description</td> <td><textarea name="product_description" cols="20" rows="10" ></textarea></td> </tr> <tr> <td><input type="submit" value="Add Product" name="insert_post"></td> </tr> </table> </form> </body> </html>
PHP处理部分:
<?php if( isset($_POST['insert_post'])) { $product_title = $_POST['$product_title']; $product_category = $_POST['$product_category']; $product_featured = $_POST['product_featured']; $product_price = $_POST['$product_price']; $product_keywords = $_POST['$product_keywords']; $product_description = $_POST['$product_description']; $product_image = $_FILES['product_image']['name']; $product_image_tmp = $_FILES['product_image']['tmp_name']; echo $insert_product = " insert into products (product_cat, product_featured, product_title, product_price, product_desc,product_image,product_keywords) values ('$product_category','$product_featured','$product_title','$product_price','$product_description','$product_image','$product_keywords','$product_keywords')"; } ?>
输出的INSERT语句结果:
insert into products (product_cat, product_featured, product_title, product_price, product_desc,product_image,product_keywords) values ('','1','','','','champagne culture logo men.png','','')
问题分析与解决办法
一眼就看到问题所在了——你在获取$_POST值的时候,键名前面多写了美元符号$!
比如你写的是$_POST['$product_title'],但表单里的输入框name属性是product_title,正确的写法应该是$_POST['product_title'](去掉键名里的$)。而product_featured你写的是对的,所以能拿到值;product_image是通过$_FILES获取的,不受这个错误影响,所以也正常。
另外你的INSERT语句还有个小问题:字段列表是7个,但值列表里写了8个(最后多了一个$product_keywords),这会导致SQL语法错误,也要一起修正。
修正后的PHP代码:
<?php if( isset($_POST['insert_post'])) { // 去掉$_POST键名里的$符号 $product_title = $_POST['product_title']; $product_category = $_POST['product_category']; $product_featured = $_POST['product_featured']; $product_price = $_POST['product_price']; $product_keywords = $_POST['product_keywords']; $product_description = $_POST['product_description']; $product_image = $_FILES['product_image']['name']; $product_image_tmp = $_FILES['product_image']['tmp_name']; // 修正字段和值的数量匹配问题 echo $insert_product = "INSERT INTO products (product_cat, product_featured, product_title, product_price, product_desc, product_image, product_keywords) VALUES ('$product_category','$product_featured','$product_title','$product_price','$product_description','$product_image','$product_keywords')"; } ?>
额外建议(重要):
你现在的代码直接把用户输入拼到SQL语句里,存在严重的SQL注入风险。建议改用mysqli预处理语句或者PDO来处理数据库操作,举个mysqli预处理的例子:
// 假设$con是你的数据库连接对象 $stmt = $con->prepare("INSERT INTO products (product_cat, product_featured, product_title, product_price, product_desc, product_image, product_keywords) VALUES (?, ?, ?, ?, ?, ?, ?)"); // 绑定参数:"issssss" 表示参数类型依次是整数、字符串、字符串、字符串、字符串、字符串、字符串 $stmt->bind_param("issssss", $product_category, $product_featured, $product_title, $product_price, $product_description, $product_image, $product_keywords); $stmt->execute();
这样能有效防止SQL注入,让你的代码更安全。
内容的提问来源于stack exchange,提问作者Oshane Baker
相关产品推荐
相关产品推荐

