检查mysql中是否存在用户id


Check if user id exists in mysql

我有一个用户ID存储在变量$_SESSION['user_ID']中。对于编辑帖子,这个ID应该与mysql表中的"user"字段匹配。

如何设置一个语句来检查这些变量是否匹配?

$query="SELECT*FROM tablename WHERE user='"$使用者"'";

// EDIT THE POST
$user = $_SESSION['user_id'];
// if the 'id' variable is set in the URL, we know that we need to edit a record
if (isset($_GET['id']))
{
    // if the form's submit button is clicked, we need to process the form
    if (isset($_POST['submit']))
    {
        // make sure the 'id' in the URL is valid
        if (is_numeric($_POST['id']))
        {
            // get variables from the URL/form
            $id = $_POST['id'];
            $elv = htmlentities($_POST['elv'], ENT_QUOTES);
            $vald = htmlentities($_POST['vald'], ENT_QUOTES);
            $art = htmlentities($_POST['art'], ENT_QUOTES);
            $dato = htmlentities($_POST['dato'], ENT_QUOTES);
            $vekt = (int)$_POST['vekt'];
            $lengde = (int)$_POST['lengde'];
            $flue = htmlentities($_POST['flue'], ENT_QUOTES);
            $gjenutsatt = (int)$_POST['gjenutsatt'];
            $kjonn = (int)$_POST['kjonn'];
            $bilde = htmlentities($_POST['bilde'], ENT_QUOTES);
            $user = $_SESSION['user_id'];
            // check that required fields are not empty
            if ($elv == '' || $vald == '' || $art == '' || $dato == '' || $vekt == '' || $kjonn == '')
            {
                // if they are empty, show an error message and display the form
                $error = 'Du må fylle ut de påkrevde feltene!';
                renderForm($elv, $vald, $art, $dato, $vekt, $lengde, $flue, $gjenutsatt, $kjonn, $bilde, $user, $error, $id);
            }
            else
            {
                // if everything is fine, update the record in the database
                if ($stmt = $mysqli->prepare("UPDATE fisk SET elv = ?, vald = ?, art = ?, dato = ?, vekt = ?, lengde = ?, flue = ?, gjenutsatt = ?, kjonn= ?, bilde = ?, user = ?
                    WHERE id=? AND user=?"))
                {
                    $stmt->bind_param("ssssiisiisii", $elv, $vald, $art, $dato, $vekt, $lengde, $flue, $gjenutsatt, $kjonn, $bilde, $user, $id);
                    $stmt->execute();
                    $stmt->close();
                }
                // show an error message if the query has an error
                else
                {
                    echo "ERROR: could not prepare SQL statement.";
                }
                // redirect the user once the form is updated
                header("Location: /");
            }
        }
        // if the 'id' variable is not valid, show an error message
        else
        {
            echo "Error!";
        }
    }
$query = "SELECT  * FROM table_name WHERE id = $id AND user = $_SESSION['user_id'];

这将获得id为$id的帖子,该帖子由用户id存储在$_SESSION['User_id']中的用户发布;

由于如果用户试图编辑他自己的帖子之外的帖子,您希望显示一条错误消息,因此您应该通过$id获取帖子的详细信息,然后检查"user"字段,使其与当前会话中的user_id匹配。

$query = "SELECT  * FROM table_name WHERE id = $id";
$rs    = mysql_query($query);
if(mysql_num_rows($rs)>0){
// post exists 
    while($row = mysql_fetch_assoc($rs)){
        if($row['user']===$_SESSION['user_id']){
            // allow the edit.
        }else{
            // show error user is not authorized to do the edits
        }
    }else{
        // show the error this is not a valid id; no posts exists with the given id
    }
}