PHP+MySQL数据更新表单问题:变量未定义/无法更新求助
问题分析与修复方案
咱们先拆解你遇到的两个核心问题:
- 最初的变量未定义报错:是因为表单根本没提交数据,
$_POST里的所有变量都不存在,直接执行SQL自然会报错。 - 加了
isset($_POST)后显示“Not Update”:是因为你的表单提交逻辑完全错了,点击按钮根本没触发表单提交,update.php永远接收不到$_POST['update'],所以进不了更新逻辑。
下面一步步给你修复:
第一步:修复编辑页面的表单提交逻辑
你的编辑页面里,每个表格行的<form>标签包裹了行内容,但提交按钮却放在了<table>外面的<a>标签里——这导致点击按钮时,没有任何表单被提交!咱们把提交按钮放到每个行的<form>内部,同时给所有HTML属性加上引号(避免语法解析错误)。
修正后的编辑页面代码:
<?php // connect to the database include('mysql_connect.php'); // get results from database $result = mysqli_query($conn,"SELECT * FROM products") or die(mysqli_error()); ?> <html> <head> <title>Update Data</title> <link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.1.1/css/bootstrap.min.css" > <script src="https://stackpath.bootstrapcdn.com/bootstrap/4.1.1/js/bootstrap.min.js"></script> </head> <body> <h1>Product list update</h1> <hr> <table style="width:50%!important" class='table'> <tr bgcolor='#CCCCCC'> <th>SKU</th> <th>Name</th> <th>Price</th> <th>Type</th> <th>Details</th> <th>Action</th> <!-- 新增操作列放提交按钮 --> </tr> <?php while ($res = mysqli_fetch_array($result)){ echo "<tr><form action='update.php' method='post'>"; echo "<td><input type='text' name='sku_p' value='".$res['sku_product']."'></td>"; echo "<td><input type='text' name='name_p' value='".$res['name_product']."'></td>"; echo "<td><input type='text' name='price_p' value='".$res['price_product']."'></td>"; echo "<td><input type='text' name='type_p' value='".$res['type_product']."'></td>"; echo "<td> Size for DVD: <input type='text' name='sizedvd_p' value='".$res['sizedvd_product']."'><br> Weight for Book: <input type='text' name='weightbook_p' value='".$res['weightbook_product']."'><br> For Furniture<br> H: <input type='text' name='heightfurn_p' value='".$res['heightfurn_product']."'><br> W: <input type='text' name='widthfurn_p' value='".$res['widthfurn_product']."'><br> L: <input type='text' name='lengthfurn_p' value='".$res['lengthfurn_product']."'><br></td>"; echo "<input type='hidden' name='id_p' value='".$res['id_product']."'>"; echo "<td><input type='submit' name='update' value='Save Changes'></td>"; // 把提交按钮放到form内部 echo "</form></tr>"; } ?> </table> <a href="index.php">Home</a><br> </body> </html>
第二步:修复update.php的逻辑与安全问题
你原来的代码直接把$_POST拼到SQL里,这会导致严重的SQL注入漏洞,必须用预处理语句修复。同时完善连接逻辑和错误提示:
修正后的update.php代码:
<?php // connect to the database include('mysql_connect.php'); // 和编辑页面共用连接文件,避免重复代码 // Update logic if(isset($_POST['update'])){ // 先获取表单数据 $id = $_POST['id_p']; $sku = $_POST['sku_p']; $name = $_POST['name_p']; $price = $_POST['price_p']; $type = $_POST['type_p']; $sizedvd = $_POST['sizedvd_p']; $weightbook = $_POST['weightbook_p']; $heightfurn = $_POST['heightfurn_p']; $widthfurn = $_POST['widthfurn_p']; $lengthfurn = $_POST['lengthfurn_p']; // 使用预处理语句,彻底避免SQL注入 $stmt = mysqli_prepare($conn, "UPDATE products SET name_product=?, price_product=?, sku_product=?, type_product=?, sizedvd_product=?, weightbook_product=?, heightfurn_product=?, widthfurn_product=?, lengthfurn_product=? WHERE id_product=?"); // 绑定参数("sssssssssi"对应字符串*9 + 整数*1) mysqli_stmt_bind_param($stmt, "sssssssssi", $name, $price, $sku, $type, $sizedvd, $weightbook, $heightfurn, $widthfurn, $lengthfurn, $id); if(mysqli_stmt_execute($stmt)){ echo "Data updated successfully!"; // 可选:更新成功后跳回编辑页面,避免重复提交 // header("Location: 你的编辑页面文件名.php"); // exit; } else { echo "Update failed: " . mysqli_error($conn); } mysqli_stmt_close($stmt); } else { echo "No update request received."; } mysqli_close($conn); ?>
额外提醒
- 永远不要直接把用户输入(比如
$_POST)拼接到SQL语句里,预处理是PHP操作数据库的标准安全做法。 - 可以在更新成功后用
header()跳回编辑页面,提升用户体验。
内容的提问来源于stack exchange,提问作者Artyom
相关产品推荐
相关产品推荐

