不能过滤空格,查询返回所有用户


Can't filter whitespace, Query returns all users

我有一个用户界面,用户可以在其中键入一个人的名字和姓氏。只要我在搜索框中不输入任何内容,就不会找到任何用户。但是只要我输入一个空格,就会返回数据库中的每个用户。我修剪输入字符串并检查空白:

if (isset($_GET['lastname'])) {
    $lastname_value = trim($_GET['lastname']);
    //This Line is only used for setting the Text again in the Search Box       
    $tpl->setVariable('ss-search-lastname-value', $lastname_value);
}
if(isset($_GET['firstname'])) {
    $firstname_value = trim($_GET['firstname']);
    $tpl->setVariable('ss-search-firstname-value',$firstname_value);
}

之后,我编写搜索查询:

$sql = "SELECT e.`user_id`, e.`firstname`, e.`lastname`, e.`email`
            FROM `employees` as e
            WHERE 1";
if($lastname_value!="") {
    $sql .=" AND e.`lastname` ='$lastname_value'";
}
if($firstname_value!="") {
    $sql .=" AND e.`firstname` ='$firstname_value'";
}

一个正常的搜索返回期望的用户和正确的名字和姓氏,如果我什么都不输入并开始搜索,则不返回任何结果。然而,在搜索框中的一个空白,我得到了所有的用户。我怎样才能解决这个问题呢?

您需要首先决定是否要搜索:

$doSearch = false;
$hasLastname = $lastname_value != "";
$hasFirstname = $firstname_value != "";
$doSearch = $hasLastname || $hasFirstname;
if ($doSearch)
{
    $sql = "SELECT e.`user_id`, e.`firstname`, e.`lastname`, e.`email`
            FROM `employees` as e
            WHERE 1";
    if($lastname_value!="") {
        $sql .=" AND e.`lastname` ='$lastname_value'";
    }
    if($firstname_value!="") {
        $sql .=" AND e.`lastname` ='$firstname_value'";
    }
    ...
}