如何实现输入姓名/邮箱/用户名/出生日期时匹配显示用户数据?
修复Welcome.php的用户搜索功能问题
嗨,我看了你的代码,发现搜索功能没正常工作主要是几个关键逻辑和变量的问题,我帮你修正了代码,应该能实现你想要的搜索效果——输入姓名、用户名、邮箱或出生日期后,只显示匹配的用户行:
<?php session_start(); if (!isset($_SESSION['id'])) { header('location:login.php'); } ?> <!DOCTYPE html> <html> <body> <?php include_once 'connect.php'; $query = mysqli_query($mysqli, "select * from `users` where userid='" . $_SESSION['id'] . "'"); $row = mysqli_fetch_array($query); echo 'Welcome - ' . $row['username']; ?> <br> <a href="logout.php">Logout</a> <br><br> <?php include_once 'connect.php'; // 处理搜索逻辑 $searchKeyword = ''; if (isset($_POST["happy"])) { $searchKeyword = trim($_POST["happy"]); } // 构建查询语句:如果有搜索关键词则执行模糊查询,否则显示所有用户 if (!empty($searchKeyword)) { // 使用预处理语句防止SQL注入,同时处理多字段模糊匹配 $sql = "SELECT * FROM users WHERE name LIKE ? OR username LIKE ? OR email LIKE ? OR Date_of_birth LIKE ?"; $stmt = mysqli_prepare($mysqli, $sql); $likeKeyword = "%{$searchKeyword}%"; mysqli_stmt_bind_param($stmt, "ssss", $likeKeyword, $likeKeyword, $likeKeyword, $likeKeyword); mysqli_stmt_execute($stmt); $result = mysqli_stmt_get_result($stmt); } else { // 显示所有用户 $result = mysqli_query($mysqli, "SELECT * FROM users"); } // 输出表格 echo "<table border='1'> <tr> <th>User_ID</th> <th>Name</th> <th>Username</th> <th>E-mail</th> <th>Department</th> <th>Date_of_birth</th> <th>Age</th> <th>Image</th> <th>Action</th> <th>Action</th> </tr>"; while ($row = mysqli_fetch_array($result)) { echo "<tr>"; echo "<td>" . $row['userid'] . "</td>"; echo "<td>" . $row['name'] . "</td>"; echo "<td>" . $row['username'] . "</td>"; echo "<td>" . $row['email'] . "</td>"; echo "<td>" . $row['department'] . "</td>"; echo "<td>" . $row['Date_of_birth'] . "</td>"; echo "<td>" . $row['age'] . "</td>"; echo "<td><img alt='image' style='width:100px;height:50px;' src='upload/" . $row['filename'] . "'></td>"; echo "<td> <a href='editform.php?id=" . $row['userid'] . "'>Edit</a></td>"; echo "<td> <a href='deleteform.php?id=" . $row['userid'] . "'>Delete</a></td>"; echo "</tr>"; } echo "</table>"; // 搜索错误提示 if (isset($_POST["happy"]) && empty($searchKeyword)) { echo '<br>'; echo "No letter entered"; } ?> <form method="post"> <br> Search: <input type="text" name="happy" value="<?php echo htmlspecialchars($searchKeyword); ?>"><br><br> <input type="submit" value="Submit"> </form> </body> </html>
主要修改点说明:
- 变量修正:原代码里用了未定义的
$name变量,现在改为从$_POST["happy"]获取搜索关键词并赋值给$searchKeyword。 - SQL注入防护:使用了mysqli预处理语句(
mysqli_prepare、mysqli_stmt_bind_param),避免直接拼接SQL语句带来的安全风险。 - 查询逻辑优化:根据是否有搜索关键词,动态切换查询——有关键词时执行多字段模糊匹配,无关键词时显示所有用户。
- 用户体验优化:搜索框会保留上次输入的关键词,方便用户调整搜索内容。
- 逻辑整理:把搜索相关的逻辑和表格渲染逻辑分开,代码更清晰,避免原代码里混乱的查询顺序。
内容的提问来源于stack exchange,提问作者user9827538
相关产品推荐
相关产品推荐

