如何识别循环生成表单中被提交验证的具体表单
Hey there! I see you're generating multiple forms from database entries and need to identify which specific form was submitted to run the right SQL operations. Let's break down the issues in your current code and fix them step by step:
Key Issues in Your Current Code
- Disabled inputs don't get submitted: Your
audit_request_idinput is marked asdisabled, which means its value won't be sent to the server when the form is submitted. That's why you can't capture the correct ID. - SQL injection vulnerability: Directly concatenating values into SQL queries is a major security risk—you should use prepared statements instead.
- Incorrect $_POST handling: The line
$audit_request_id = stripslashes('audit_request_id');is hardcoding the string "audit_request_id" instead of fetching the actual submitted value from$_POST.
Fixed Code with Explanations
Here's the revised version of your code that addresses all these problems:
<?php require_once 'header.php'; if (!$loggedin) die(); $result = queryMysql("SELECT * FROM audit_requests"); $num_rows = $result->num_rows; echo "<div class='main'><h3>$num_rows audit requests found!</h3>"; while ($row = $result->fetch_array(MYSQLI_ASSOC)) { $requester = htmlspecialchars(stripslashes($row['user'])); $audit_request_id = htmlspecialchars(stripslashes($row['audit_request_id'])); echo <<<_END <form method='post' action='audit_listings.php' enctype='multipart/form-data'> <span class='text'><br>Audit request number</span> <!-- Use readonly instead of disabled so the value is submitted --> <input readonly type='text' maxlength='10' name='audit_request_id_display' value='$audit_request_id'> <!-- Hidden field ensures the ID is reliably passed to the server --> <input type='hidden' name='audit_request_id' value='$audit_request_id'> <span class='text'><br>Auditee name</span> <input readonly type='text' maxlength='16' name='user' value='$requester'> _END; if (getCategory($user) == 'Auditor') { echo "<input type='submit' value='Apply for this audit request'>"; } echo <<<_END </form></div><br> _END; } if (isset($_POST['audit_request_id'])) { // Assume $connection is your database connection variable $audit_request_id = mysqli_real_escape_string($connection, $_POST['audit_request_id']); $applicant = mysqli_real_escape_string($connection, $user); $org_name = mysqli_real_escape_string($connection, $org_name); $address = mysqli_real_escape_string($connection, $address); $city = mysqli_real_escape_string($connection, $city); // Use prepared statements to eliminate SQL injection risks // 1. Copy audit request to audit plan $stmt = $connection->prepare("INSERT INTO audit_plan SELECT * FROM audit_requests WHERE audit_request_id = ?"); $stmt->bind_param("s", $audit_request_id); $stmt->execute(); $stmt->close(); // 2. Update the applicant in the audit plan $stmt = $connection->prepare("UPDATE audit_plan SET applicant = ? WHERE audit_request_id = ?"); $stmt->bind_param("ss", $applicant, $audit_request_id); $stmt->execute(); $stmt->close(); // 3. Send notification message (fixed missing closing parenthesis) $stmt = $connection->prepare("INSERT INTO messages VALUES('', 'TrustusChain', ?, ?, '', ?)"); $stmt->bind_param("sss", $org_name, $address, $city); $stmt->execute(); $stmt->close(); } ?>
What Changed?
- Replaced
disabledwithreadonly: This keeps inputs uneditable but ensures their values are sent with the form. We also added a hidden field foraudit_request_idto guarantee the ID is captured reliably. - Added
htmlspecialchars(): Prevents cross-site scripting (XSS) attacks when outputting database values to the HTML page. - Implemented prepared statements: Separates SQL logic from user data to eliminate injection risks entirely.
- Fixed $_POST value retrieval: Now correctly fetches the submitted
audit_request_idfrom$_POSTinstead of hardcoding a string. - Corrected the
INSERT INTO messagesquery: Fixed the missing closing parenthesis that would have caused a SQL error.
With these changes, when a user clicks "Apply for this audit request", the corresponding audit_request_id will be sent to the server, and your SQL operations will target the exact entry you need.
内容的提问来源于stack exchange,提问作者Mehdi
相关产品推荐
相关产品推荐

