如何将数据库查询生成的表格内容转为可点击链接
解决班级表格动态链接问题&代码优化
嘿,我来帮你搞定这个动态链接的需求,顺便给你提几个能让代码更安全、更整洁的小建议:
1. 修复动态链接的核心问题
你注释掉的代码里有两个关键错误:
- 你用了
$row['id'],但你的SQL查询里并没有id字段,实际应该对应查询中的Classes.Class_id,也就是$row['Class_id'] - PHP双引号字符串里的数组索引需要用
{}包裹,否则会触发语法错误
如果想把班级ID做成可点击的链接,循环部分可以这么写:
while ($row = $results->fetchArray(SQLITE3_ASSOC)) { echo ("<tr>"); // 把Class_id字段做成跳转链接 echo "<td><a href='class_detail.php?class_id={$row['Class_id']}'>{$row['Class_id']}</a></td>"; // 输出剩余字段 echo "<td>{$row['Section_id']}</td>"; echo "<td>{$row['className']}</td>"; echo "<td>{$row['Subject']}</td>"; echo "<td>{$row['Location']}</td>"; echo ("</tr>"); }
要是想让整行都能点击(用户体验更好),可以用JS配合CSS实现:
while ($row = $results->fetchArray(SQLITE3_ASSOC)) { echo "<tr onclick=\"window.location='class_detail.php?class_id={$row['Class_id']}'\" style='cursor: pointer;'>"; echo "<td>{$row['Class_id']}</td>"; echo "<td>{$row['Section_id']}</td>"; echo "<td>{$row['className']}</td>"; echo "<td>{$row['Subject']}</td>"; echo "<td>{$row['Location']}</td>"; echo "</tr>"; }
2. 修复重复表头的问题
你现在的代码先手动输出了一组表头,又循环输出查询的列名,导致表格出现两行重复表头。建议统一成清晰的手动表头:
echo "<table>"; // 统一输出表头 echo "<tr> <th>Course ID</th> <th>Section ID</th> <th>Class Name</th> <th>Subject</th> <th>Location</th> </tr>";
3. 紧急修复SQL注入风险!
你直接把$_SESSION['user']拼进SQL语句里,这是非常危险的SQL注入漏洞!任何人都可以构造恶意值篡改你的数据库。改用SQLite3的预处理语句来解决:
// 替换原查询语句,用?作为参数占位符 $classquery = "SELECT DISTINCT Classes.Class_id, Classes.Section_id, Classes.className, Classes.Subject, Classes.Location FROM Classes JOIN StudentClasses ON StudentClasses.Class_id = Classes.Class_id AND StudentClasses.Section_id = Classes.Section_id JOIN Students ON StudentClasses.Student_id = Students.Student_id WHERE Students.Username = ?;"; // 预处理+绑定参数 $stmt = $db->prepare($classquery); $stmt->bindValue(1, $username, SQLITE3_TEXT); $results = $stmt->execute();
完整修正后的代码
把上面的改动整合后,最终代码如下:
<!DOCTYPE html> <?php include("secure.php") ?> <html lang= "en"> <head> <title> Class Index </title> <meta charset= "utf-8" /> <link rel="stylesheet" href="class_coverpage.css" /> </head> <body> <?php $username = $_SESSION['user']; // 安全的预处理查询 $classquery = "SELECT DISTINCT Classes.Class_id, Classes.Section_id, Classes.className, Classes.Subject, Classes.Location FROM Classes JOIN StudentClasses ON StudentClasses.Class_id = Classes.Class_id AND StudentClasses.Section_id = Classes.Section_id JOIN Students ON StudentClasses.Student_id = Students.Student_id WHERE Students.Username = ?;"; $stmt = $db->prepare($classquery); $stmt->bindValue(1, $username, SQLITE3_TEXT); $results = $stmt->execute(); if (!$results) { echo("<h2>Error: The query could not be executed.</h2>"); $error = $db->lastErrorMsg(); echo("<p>$error<p>"); exit; } // 输出表格 echo "<table>"; echo "<tr> <th>Course ID</th> <th>Section ID</th> <th>Class Name</th> <th>Subject</th> <th>Location</th> </tr>"; // 带动态链接的表格行 while ($row = $results->fetchArray(SQLITE3_ASSOC)) { echo "<tr>"; echo "<td><a href='class_detail.php?class_id={$row['Class_id']}'>{$row['Class_id']}</a></td>"; echo "<td>{$row['Section_id']}</td>"; echo "<td>{$row['className']}</td>"; echo "<td>{$row['Subject']}</td>"; echo "<td>{$row['Location']}</td>"; echo "</tr>"; } echo "</table>"; ?> </body> </html>
这样每个班级的链接都会带上对应的class_id参数(比如class_detail.php?class_id=cs120),代码也更安全、整洁啦~
内容的提问来源于stack exchange,提问作者Rob
相关产品推荐
相关产品推荐

