自定义论坛发布新主题时出现空白页问题求助
Hey there! Let's figure out why you're hitting that blank page instead of redirecting to your subcategory after creating a topic. I spotted several issues in your code that are causing this—let's go through them one by one:
1. Chinese Full-Width Quotes Are Breaking Your Code
This is the most immediate cause of your blank page. Look at the quotes in both files:
- In
newtopic.php, your form action uses”(full-width double quotes) instead of"(standard double quotes):// Wrong echo "<form action='/forum-tutorial/addnewtopic.php? cid=".$_GET['cid'].”&scid=".$_GET['scid'].”' method='POST'>"; // Correct echo "<form action='/forum-tutorial/addnewtopic.php?cid=".$_GET['cid']."&scid=".$_GET['scid']."' method='POST'>"; - In
addnewtopic.php, your SQL query also uses full-width quotes around the variables:// Wrong $insert = mysqli_query($con, "INSERT INTO users (`username`, `password`) VALUES ('".$newuser.”', '".$newpwd.”');"); // Correct $insert = mysqli_query($con, "INSERT INTO users (`username`, `password`) VALUES ('".$newuser."', '".$newpwd."');");
PHP doesn't recognize full-width quotes as string delimiters, so these lines throw syntax errors that cause the blank page.
2. No Session Check or Request Validation in addnewtopic.php
Right now, anyone could directly access addnewtopic.php and trigger errors. You need to:
- Start the session to verify the user is logged in
- Check if the request is actually a POST request (so direct visits don't cause blank pages)
- Add error handling for your database query
3. Missing exit() After header() Redirect
When you use header("Location: ..."), you must add exit() or die() immediately after. Otherwise, PHP might continue executing code after the redirect, which can cause output issues or prevent the redirect from working properly.
4. Critical SQL Injection Vulnerability
You're directly inserting user input into your SQL query—this is a huge security risk. Always use prepared statements to sanitize user input.
Fixed Version of addnewtopic.php
Here's a revised version that fixes all these issues (note: I assumed your topics table has fields like topic_title, topic_content, etc.—adjust to match your actual schema):
<?php // Enable error reporting for debugging (remove in production) error_reporting(E_ALL); ini_set('display_errors', 1); session_start(); include ('dbconn.php'); // Only process if it's a POST request and user is logged in if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_SESSION['username'])) { // Sanitize input (or use prepared statements for better security) $topicTitle = mysqli_real_escape_string($con, $_POST['topic']); $content = mysqli_real_escape_string($con, $_POST['content']); $cid = mysqli_real_escape_string($con, $_GET['cid']); $scid = mysqli_real_escape_string($con, $_GET['scid']); $username = $_SESSION['username']; // Use prepared statement to prevent SQL injection $stmt = $con->prepare("INSERT INTO topics (topic_title, topic_content, topic_cid, topic_scid, topic_author) VALUES (?, ?, ?, ?, ?)"); $stmt->bind_param("sssis", $topicTitle, $content, $cid, $scid, $username); if ($stmt->execute()) { // Redirect to the subcategory page header("Location: /forum-tutorial/subcategory.php?cid=".$cid."&scid=".$scid); exit(); // Critical to stop execution after redirect } else { echo "Error creating topic: " . $stmt->error; } $stmt->close(); } else { // Redirect to login if user isn't logged in or request is invalid header("Location: /forum-tutorial/login.php?status=login-fail"); exit(); } ?>
Quick Fix for newtopic.php
Update the form action line to use standard quotes and remove the extra space in the URL:
echo "<form action='/forum-tutorial/addnewtopic.php?cid=".$_GET['cid']."&scid=".$_GET['scid']."' method='POST'>";
Bonus Debugging Tip
If you still see a blank page, enable PHP error reporting temporarily by adding these lines at the top of your PHP files:
error_reporting(E_ALL); ini_set('display_errors', 1);
This will show you exactly what errors are occurring instead of a blank screen.
内容的提问来源于stack exchange,提问作者Anonymus96

