You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP从URL的$_GET获取'site'索引时出现Undefined Index错误

修复PHP编辑脚本的Undefined Index错误与安全优化

嘿,我看到你的编辑脚本遇到了Undefined Index的问题,还有几个潜在的安全和逻辑漏洞,一起来搞定它们:

1. 解决$_GET['site']的Undefined Index错误

这个错误出现在直接访问edit.php而没有带上site参数的时候,比如用户直接输入URL而不是从列表页点击编辑链接。我们需要先检查参数是否存在,不存在就跳回首页:

// 替换原来直接获取$sitenumber的代码
if (!isset($_GET['site'])) {
    // 没有site参数,跳回首页
    header("Location: index.php");
    exit(); // 一定要加exit,防止后续代码执行
}
// 保存原始站点编号,后续更新用这个,避免用户修改表单里的编号导致更新错数据
$original_sitenumber = $_GET['site'];

// 选择与该站点关联的数据
$result = mysqli_query($mysqli, "SELECT * FROM sites WHERE sitenumber='".$original_sitenumber."'");
// 这里也可以加个判断,如果没查到数据就提示错误
if (mysqli_num_rows($result) === 0) {
    echo "<font color='red'>找不到对应的站点数据!</font>";
    exit();
}
$res = mysqli_fetch_array($result);
// 直接把查询结果赋值给变量,不用while循环(因为站点编号应该是唯一的)
$sitenumber = $res['sitenumber'];
$videolink = $res['videolink'];
$daynight = $res['daynight'];
$maxtents = $res['maxtents'];
$maxpersons = $res['maxpersons'];
$geography = $res['geography'];
$view = $res['view'];
$forestcover = $res['forestcover'];
$waterfront = $res['waterfront'];
$firepit = $res['firepit'];
$description = $res['description'];
$reslink = $res['reslink'];

2. 修复表单提交时的参数丢失问题

你的表单action是edit.php,提交后URL里的site参数会丢失,导致提交时$_GET['site']不存在,触发错误。需要把site参数加到表单的action里:

<form name="form1" method="post" action="edit.php?site=<?php echo $original_sitenumber; ?>">

3. 修复更新逻辑的漏洞与SQL注入问题

原代码用POST过来的sitenumber作为更新条件,万一用户修改了表单里的站点编号,就会错误地更新其他站点的数据!应该用从URL获取的$original_sitenumber作为更新条件。

同时,必须修复SQL注入问题——直接把用户输入拼到SQL里是非常危险的,用mysqli预处理语句来解决:

if(isset($_POST['update']) && isset($_GET['site'])) {
    // 获取POST数据
    $sitenumber = $_POST['sitenumber'];
    $videolink = $_POST['videolink'];
    $daynight = $_POST['daynight'];
    $maxtents = $_POST['maxtents'];
    $maxpersons = $_POST['maxpersons'];
    $geography = $_POST['geography'];
    $view = $_POST['view'];
    $forestcover = $_POST['forestcover'];
    $waterfront = $_POST['waterfront'];
    $firepit = $_POST['firepit'];
    $description = $_POST['description'];
    $reslink = $_POST['reslink'];

    // 空字段检查(保留你的原有逻辑)
    $has_error = false;
    if(empty($sitenumber)) {
        echo "<font color='red'>Site Number字段为空。</font><br/>";
        $has_error = true;
    }
    if(empty($videolink)) {
        echo "<font color='red'>YouTube Link字段为空。</font><br/>";
        $has_error = true;
    }
    // ...其他字段检查逻辑保持不变,记得将$has_error设为true

    if (!$has_error) {
        // 使用预处理语句更新数据,防止SQL注入
        $stmt = $mysqli->prepare("UPDATE sites SET sitenumber=?, videolink=?, daynight=?, maxtents=?, maxpersons=?, geography=?, view=?, forestcover=?, waterfront=?, firepit=?, description=?, reslink=? WHERE sitenumber=?");
        // 绑定参数:s=字符串,i=整数,对应每个字段的类型
        $stmt->bind_param("ssiiiiiiisss", $sitenumber, $videolink, $daynight, $maxtents, $maxpersons, $geography, $view, $forestcover, $waterfront, $firepit, $description, $reslink, $original_sitenumber);
        
        if ($stmt->execute()) {
            header("Location: index.php");
            exit();
        } else {
            echo "<font color='red'>更新失败:" . $stmt->error . "</font>";
        }
        $stmt->close();
    }
}

4. 修复表单select标签的错误

原select标签的value属性是无效的,应该在对应的option上添加selected属性来默认选中:

<tr>
    <td>Day or Overnight</td>
    <td>
        <select name="daynight">
            <option value="Day" <?php echo ($daynight == 'Day') ? 'selected' : ''; ?>>Day</option>
            <option value="Overnight" <?php echo ($daynight == 'Overnight') ? 'selected' : ''; ?>>Overnight</option>
        </select>
    </td>
</tr>

额外建议:开启错误提示(开发环境)

在开发阶段,可以在代码开头加上这两行,方便调试:

error_reporting(E_ALL);
ini_set('display_errors', 1);

这样修改后,Undefined Index的问题就解决了,脚本的安全性和逻辑也更严谨啦!

内容的提问来源于stack exchange,提问作者Damien Borden

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:07:02