因此,我必须制作一个php页面,用于批准/拒绝数据库中特定行获取的一些信息。如果看到信息的管理员批准了它,他会添加一些额外的值并更新数据库中的特定行(这些额外的值在批准之前为0),但最终不起作用。我认为问题在于提交表单重定向到的approve.php文件,我认为它没有读取Admin输入的值。
以下是表单(lecturermet.php):
<div class="wrapper col3">
<div class="container">
<h1>Pending Meeting Submissions</h1>
<?php
mysql_connect("localhost","root","") or die(mysql_error());
mysql_select_db("dissdb") or die(mysql_error());
$statuscheck = 0;
$result = mysql_query("SELECT status FROM meeting WHERE status = '$statuscheck'");
if ($result != NULL) {
$result = mysql_query("SELECT id,username,date,subject,report FROM meeting WHERE status = '$statuscheck'");
while ($row = mysql_fetch_assoc($result)){
$uploader = $row['username'];
$date = $row['date'];
$subject = $row['subject'];
$report = $row['report'];
$id = $row['id'];
echo ' <font size=6> <p>Meeting: #' .$id. ' </font><br><br>Submitted by: '.$uploader.'<br>Date: ' .$date. '<br>Subject: ' .$subject. '<br>Report: ' .$report. '<br> <br></p>' ;
$showbuttons = 1;
if($showbuttons == 1) : ?>
<form>
Meeting #:
<input type="number" name="id" id="id" value='$id' min="1" max="20">
</form>
<form>
Project Progression Status (between 1 and 6):
<input type="number" name="progress" id="progress" min="1" max="6">
</form>
<form>
<br> Effort Shown (between 1 and 6):
<input type="number" name="effort" id="effort" min="1" max="6">
</form>
<form>
<br> Dissertation Projection (between 1 and 6):
<input type="number" name="projection" id="projection" min="1" max="6">
</form>
<form>
<br> Lecturer Satisfaction (between 1 and 6):
<input type="number" name="satisfaction" id="satisfaction" min="1" max="6">
</form>
<form>
<br> Overall (between 1 and 10):
<input type="number" name="mark" id="mark" min="1" max="10">
<br><br><br></form>
<form action="approve.php" method="post"
enctype="multipart/form-data">
<input type="submit" name="approve" value="Approve">
</form>
<label for="rejectinfo"><br><br><br>Rejection comments:</label>
<textarea name="rejectinfo" cols="60" rows="7" id="rejectinfo" ></textarea>
<p><form action="reject.php" method="post"
enctype="multipart/form-data">
<input type="submit" name="reject" value="Reject">
<br><br></form></p>
<?php endif;
}} ?>
</div>
</div>
这是表单重定向到的approve.php,以便更新特定行:
<?php
require "config.php";
require "lecturerarea.php";
$id = $_POST['id'];
$progress = $_POST['progress'];
$effort = $_POST['effort'];
$projection = $_POST['projection'];
$satisfaction = $_POST['satisfaction'];
$mark = $_POST['mark'];
$status = 1;
mysql_connect("localhost","root","") or die(mysql_error());
mysql_select_db("dissdb") or die(mysql_error());
mysql_query("UPDATE meeting SET 'progress'='$progress', 'effort'='$effort',
'projection'='$projection', 'satisfaction'='$satisfaction', 'mark'='$mark', 'status'='$status' WHERE id = '$id'");
echo "The meeting submission is approved! <br> Redirecting now ....";
header("Refresh: 3; lecturerarea.php");
?>
删除列名周围的引号。这些不是正确的标识符。
即:SET 'progress'='$progress'
其应读作(使用回溯示例)
SET `progress`='$progress' // etc.
或者删除引号并对其他引号执行相同操作。
SET progress='$progress' // etc.
如果启用错误报告,就会发出这样的信号。
error_reporting(E_ALL);
ini_set('display_errors', 1);
也称为or die(mysql_error())
至mysql_query()
。
编辑:
您还有多个<form></form>
标记。将所有内容放入一个<form>...</form>
中,再加上您需要指定的方法。
<form method="post">
如果省略,则<form>
默认为GET
。
用于数据库插入的所有变量都是$_POST
。
这等于GET
方法
<form>
<br> Overall (between 1 and 10):
<input type="number" name="mark" id="mark" min="1" max="10">
<br><br><br></form>
并且不会被输入到DB中。
它应该读作
<form method="post">
<br> Overall (between 1 and 10):
<input type="number" name="mark" id="mark" min="1" max="10">
<br><br><br></form>
其他人也一样。
至于headers already sent
,请从header
上方删除echo
,或者如果希望它回显消息,请使用元刷新。
理想情况下,这就是你应该做的:
<form action="approve.php" method="post" enctype="multipart/form-data">
Meeting #:
<input type="number" name="id" id="id" value='$id' min="1" max="20">
Project Progression Status (between 1 and 6):
<input type="number" name="progress" id="progress" min="1" max="6">
<br> Effort Shown (between 1 and 6):
<input type="number" name="effort" id="effort" min="1" max="6">
<br> Dissertation Projection (between 1 and 6):
<input type="number" name="projection" id="projection" min="1" max="6">
<br> Lecturer Satisfaction (between 1 and 6):
<input type="number" name="satisfaction" id="satisfaction" min="1" max="6">
<br> Overall (between 1 and 10):
<input type="number" name="mark" id="mark" min="1" max="10">
<br><br><br>
<input type="submit" name="approve" value="Approve">
<label for="rejectinfo"><br><br><br>Rejection comments:</label>
<textarea name="rejectinfo" cols="60" rows="7" id="rejectinfo" ></textarea>
<input type="submit" name="reject" value="Reject">
<br><br>
</form>
旁注:
您当前的代码对SQL注入是开放的
使用准备好的语句,或将PDO与准备好的报表一起使用。
好吧,你会得到错误,因为当你点击提交批准时,你只接受该表单的值,所以如果你想要投影的数据,其他人会做类似的事情。
<form action="approve.php" method="post"
enctype="multipart/form-data">
<input type="submit" name="approve" value="Approve">
<br> Dissertation Projection (between 1 and 6):
<input type="number" name="projection" id="projection" min="1" max="6">
</form>
以及其他输入。