PHP中如何在页面间传递动态数据库值并通过mail()发送?
Hey there! Let's break down why your cart details aren't making it to the email and fix it step by step.
The Core Problems
- Wrong Data Source in Page 1: You're trying to save
$_POST['pID'],$_POST['pName']etc. to the session, but when you add a product to the cart, you're using aGETrequest ($_GET['pID']). Those$_POSTvariables are empty, so nothing gets stored. Worse, even if they worked, your cart can have multiple items—storing single variables won't capture all products. - Incorrect Data Access in Page 2: You're trying to pull single session variables (
$_SESSION['pID']), but your actual cart data lives in$_SESSION['cart'](the array you built with theobjclass).
Step 1: Clean Up Page 1 (cart.php)
First, delete these lines from page 1—they're not doing anything useful and are based on incorrect input:
$_SESSION['pID'] = $_POST['pID']; $_SESSION['pName'] = $_POST['pName']; $_SESSION['pPrice'] = $_POST['pPrice']; $_SESSION['qty'] = $_POST['qty'];
Your $_SESSION['cart'] array already holds all the cart items, so we don't need these single variables.
Step 2: Fix Page 2 (checkout.php)
We need to loop through the $_SESSION['cart'] array to build the full cart details for the email. Here's the corrected code:
<?php session_start(); require 'obj.php'; include("adminarea/includes/DBcon.php"); // First, check if the cart exists and isn't empty if(!isset($_SESSION['cart']) || count($_SESSION['cart']) === 0){ echo "<script> alert('Your cart is empty!'); window.location.href='cart.php'; </script>"; exit; // Stop execution if cart is empty } $to = "techologyy@gmail.com"; $subject = "Purchase Details:"; // Build the message by looping through the cart $message = "Thank you for your purchase!\n\n"; $message .= "Your Cart Details:\n"; $message .= "------------------------\n"; $total = 0; $cart = $_SESSION['cart']; foreach($cart as $item){ $subtotal = $item->pPrice * $item->qty; $total += $subtotal; // Add each item to the message $message .= "Product ID: " . $item->pID . "\n"; $message .= "Product Name: " . $item->pName . "\n"; $message .= "Price: €" . $item->pPrice . "\n"; $message .= "Quantity: " . $item->qty . "\n"; $message .= "Subtotal: €" . $subtotal . "\n\n"; } // Add the final total $message .= "------------------------\n"; $message .= "Total Amount: €" . $total; $headers = 'From: techologyy@gmail.com' . "\r\n"; // Send the email if(mail($to, $subject, $message, $headers)){ // Clear the cart after successful checkout unset($_SESSION['cart']); echo "<script> alert('The checkout has been done successfully! Thank you'); window.location.href='index.php'; </script>"; } else { echo "<script> alert('Oops! There was an issue sending your order confirmation.'); window.location.href='cart.php'; </script>"; } ?>
Key Improvements in Page 2:
- Cart Validation: Checks if the cart exists and has items before proceeding.
- Loop Through Cart Items: Uses
foreachto iterate over every item in$_SESSION['cart'], so all products are included in the email. - Proper Message Formatting: Builds a readable email with item details and a final total.
- Cart Cleanup: Clears the session cart after successful checkout (good practice for user experience).
- Error Handling: Checks if the email sent successfully and gives appropriate feedback.
Quick Security Note (For Future Improvement)
Right now, your page 1 uses $_GET['pID'] directly in a MySQL query:
$res = mysqli_query($connection, 'select * from product where pID='.$_GET['pID']);
This is vulnerable to SQL injection. You should use prepared statements instead. Here's how to fix that line:
$stmt = mysqli_prepare($connection, "select * from product where pID = ?"); mysqli_stmt_bind_param($stmt, "i", $_GET['pID']); mysqli_stmt_execute($stmt); $res = mysqli_stmt_get_result($stmt); $prod = mysqli_fetch_object($res);
This keeps your database safe from malicious input.
内容的提问来源于stack exchange,提问作者Redent

