You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何识别循环生成表单中被提交验证的具体表单

How to Track Which Form Submit Button Was Clicked

Hey there! I see you're generating multiple forms from database entries and need to identify which specific form was submitted to run the right SQL operations. Let's break down the issues in your current code and fix them step by step:

Key Issues in Your Current Code

  • Disabled inputs don't get submitted: Your audit_request_id input is marked as disabled, which means its value won't be sent to the server when the form is submitted. That's why you can't capture the correct ID.
  • SQL injection vulnerability: Directly concatenating values into SQL queries is a major security risk—you should use prepared statements instead.
  • Incorrect $_POST handling: The line $audit_request_id = stripslashes('audit_request_id'); is hardcoding the string "audit_request_id" instead of fetching the actual submitted value from $_POST.

Fixed Code with Explanations

Here's the revised version of your code that addresses all these problems:

<?php
require_once 'header.php';
if (!$loggedin) die();

$result = queryMysql("SELECT * FROM audit_requests");
$num_rows = $result->num_rows;

echo "<div class='main'><h3>$num_rows audit requests found!</h3>";

while ($row = $result->fetch_array(MYSQLI_ASSOC)) {
    $requester = htmlspecialchars(stripslashes($row['user']));
    $audit_request_id = htmlspecialchars(stripslashes($row['audit_request_id']));
    
    echo <<<_END
    <form method='post' action='audit_listings.php' enctype='multipart/form-data'>
        <span class='text'><br>Audit request number</span>
        <!-- Use readonly instead of disabled so the value is submitted -->
        <input readonly type='text' maxlength='10' name='audit_request_id_display' value='$audit_request_id'>
        <!-- Hidden field ensures the ID is reliably passed to the server -->
        <input type='hidden' name='audit_request_id' value='$audit_request_id'>
        
        <span class='text'><br>Auditee name</span>
        <input readonly type='text' maxlength='16' name='user' value='$requester'>
_END;

    if (getCategory($user) == 'Auditor') {
        echo "<input type='submit' value='Apply for this audit request'>";
    }

    echo <<<_END
    </form></div><br>
_END;
}

if (isset($_POST['audit_request_id'])) {
    // Assume $connection is your database connection variable
    $audit_request_id = mysqli_real_escape_string($connection, $_POST['audit_request_id']);
    $applicant = mysqli_real_escape_string($connection, $user);
    $org_name = mysqli_real_escape_string($connection, $org_name);
    $address = mysqli_real_escape_string($connection, $address);
    $city = mysqli_real_escape_string($connection, $city);

    // Use prepared statements to eliminate SQL injection risks
    // 1. Copy audit request to audit plan
    $stmt = $connection->prepare("INSERT INTO audit_plan SELECT * FROM audit_requests WHERE audit_request_id = ?");
    $stmt->bind_param("s", $audit_request_id);
    $stmt->execute();
    $stmt->close();

    // 2. Update the applicant in the audit plan
    $stmt = $connection->prepare("UPDATE audit_plan SET applicant = ? WHERE audit_request_id = ?");
    $stmt->bind_param("ss", $applicant, $audit_request_id);
    $stmt->execute();
    $stmt->close();

    // 3. Send notification message (fixed missing closing parenthesis)
    $stmt = $connection->prepare("INSERT INTO messages VALUES('', 'TrustusChain', ?, ?, '', ?)");
    $stmt->bind_param("sss", $org_name, $address, $city);
    $stmt->execute();
    $stmt->close();
}
?>

What Changed?

  • Replaced disabled with readonly: This keeps inputs uneditable but ensures their values are sent with the form. We also added a hidden field for audit_request_id to guarantee the ID is captured reliably.
  • Added htmlspecialchars(): Prevents cross-site scripting (XSS) attacks when outputting database values to the HTML page.
  • Implemented prepared statements: Separates SQL logic from user data to eliminate injection risks entirely.
  • Fixed $_POST value retrieval: Now correctly fetches the submitted audit_request_id from $_POST instead of hardcoding a string.
  • Corrected the INSERT INTO messages query: Fixed the missing closing parenthesis that would have caused a SQL error.

With these changes, when a user clicks "Apply for this audit request", the corresponding audit_request_id will be sent to the server, and your SQL operations will target the exact entry you need.

内容的提问来源于stack exchange,提问作者Mehdi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:55:10