2014-09-23 275 views





    $config = new Config; 

    $dbh = new PDO("mysql:host=" . $config->dbhost . ";dbname=" . $config->dbname, $config->dbuser, $config->dbpass); 
    $auth = new Auth($dbh, $config); 

    $fname = $_POST["fname"]; 
    $lname = $_POST["lname"]; 
    $age = $_POST["age"]; 
    $address = $_POST["address"]; 
    $city = $_POST["city"]; 
    $state = $_POST["state"]; 
    $zip = $_POST["zip"]; 
    $relationship = $_POST["relationship"]; 
    $living = $_POST["living"]; 
    $dmn = $_POST["dmn"]; 
    $dmtel = $_POST["dmtel"]; 

    //Get UID from session class 
    $uid = $auth->SessionUID($_COOKIE['authID']);  
    echo $uid; 



     $query = $dbh->prepare("INSERT INTO client VALUES (NULL, $uid, $fname, $lname, $age, $living)"); 
     $cID = $dbh->lastInsertId(); 

     $query = $dbh->prepare("INSERT INTO relationship VALUES (NULL, $uid, $cID, $relationship, $dmn, $dmtel) "); 
     $rID = $dbh->lastInsertId(); 

     $query = $dbh->prepare("INSERT INTO address VALUES (NULL, $cID, $address, $city, $state, $zip)"); 
     $aID = $dbh->lastInsertId(); 


    catch(PDOException $e){ 
     print "Error!: " . $e->getMessage(). "</br>"; 
    catch(PDOException $e){ 
     print "Error!: " . $e->getMessage(). "</br>"; 





         var formData = $("#client").serializeArray(); 

           type: "POST", 
           url: "../pages/client.php", 
           cache: false, 
           data: formData, 
           dataType: 'json', 
           success: function(login) 

            $('#message').html('<p> code: ' + login.code + '</p>'); 
            $('#message').append('<p> message: ' + login.message + '</p>'); 



         return false; 


    <div data-role="header"> 
     <a href="../views/careplan.php" data-iconshadow="false" data-icon="carat-1" data-iconpos="" data-rel="" data-ajax="false" class="login">Care Plan</a> 
     <a href="../pages/logout.php" data-iconshadow="false" data-icon="carat-1" data-iconpos="" data-rel="" data-ajax="false" class="login">Log Out</a> 

    <div data-role="main" data-theme="a" class="ui-content"> 
     <div data-role="content" > 
      <h3> Welcome <strong><?php echo $auth->getSessionUID($_COOKIE[$config->cookiename]); ?></strong></h3> 
      <br /> 
      <h2> Registration</h2> 

      <form action="" method="POST" id="client"> 
       <p>Enter information for person receiving care (Clients)</p> 

       <label for="fname">First Name:</label> 
       <input type="text" name="fname" placeholder="First Name"/> 
       <label for="lname">Last Name:</label> 
       <input type="text" name="lname" placeholder="Last Name"/> 
       <label for="age">Age:</label> 
       <input type="number" name="age" placeholder="Age"/> 
       <label for="address">Address:</label> 
       <input type="text" name="address" placeholder="Address"/> 
       <br /> 
       <label for="city">City:</label> 
       <input type="text" name="city" placeholder="City"/> 
       <br /> 
       <label for="state">State:</label> 
       <input type="text" name="state" placeholder="State"/> 
       <br /> 
       <label for="zip">Zip Code:</label> 
       <input type="number" name="zip" placeholder="00000"/> 

       <label for="relationship" >What's the Relationship to Client</label> 
       <select name="relationship" id="relationship" data-native-menu="false" > 
        <option value="Select One" data-placeholder="true">Select..</option>  
        <option value="Son">Son</option> 
        <option value="Spouse">Spouse</option> 
        <option value="Self">Self</option> 
        <option value="Daughter">Daughter</option> 
        <option value="Grand Kids">Grand Kids</option> 
        <option value="Other">Other</option> 

       <br /> 

       <label for="living" >What type of living situation</label> 
       <select name="living" id="living" data-native-menu="false"> 
        <option value="Select One" data-placeholder="true">Select</option> 
        <option value="Home">Home</option> 
        <option value="W_Caregiver">Home w/Caregiver</option> 
        <option value="inlaw">In-Law</option> 
        <option value="Other">Other</option> 
       <br /> 

       <fieldset data-role="controlgroup" data-type="horizontal" > 
        <legend>Are you the Primary Decision maker?</legend> 
        <input name="dmy" id="radio-choice-h-5a" value="On" type="radio"/> 
        <label for="radio-choice-h-5a">Yes</label> 
        <input name="dmn" id="radio-choice-h-5b" value="Off" type="radio"/> 
        <label for="radio-choice-h-5b">No</label> 


       <br /> 

       <label for="dmtel">Your Phone Number:</label> 
       <input type="tel" name="dmtel" placeholder="000-000-0000"/> 
       <br /> 

       <button type="submit" id="submit">Submit</button> 






$query = $dbh->prepare("INSERT INTO client VALUES (NULL, $uid, '$fname', '$lname', $age, $living, NULL, NULL, NULL)"); 

$query = $dbh->prepare("INSERT INTO relationship VALUES (NULL, $uid, $cID, '$relationship', '$dmn', '$dmtel') "); 

$query = $dbh->prepare("INSERT INTO address VALUES (NULL, $cID, '$address', '$city', '$state', $zip, NULL, NULL)"); 

僅供參考,您可以全部打開到SQL injections。你不應該因爲你已經在使用PDO。您需要更進一步並使用 prepared statements


這工作,感謝您對準備聲明的見解。這是它應該是什麼樣子? '$ query \t = $ dbh-> prepare(「INSERT INTO client VALUES(?,?,?,?,?,?)」);' '$ query-> execute(array(NULL,'$ uid', '$ fname','$ lname','$ age','$ living'));''$ cID = $ dbh-> lastInsertId();' – Keez 2014-09-23 23:46:10


這是一種方法。 :) – 2014-09-24 00:52:56


感謝您的幫助。我可以做什麼樣的退貨聲明來檢查未來的錯誤? – Keez 2014-09-24 01:46:35