試圖用PHP更新我的MySQL數據庫中的記錄。我是一個PHP noob,所以我假設我失去了一些明顯的東西。簡單SQL更新語句語法
我的新代碼(update-task.php) - 它提交併重定向,但記錄沒有更新。
<?php
$data = array(
'id' => $_POST['id'],
'TaskName' => $_POST['TaskName'],
'ClientName' => $_POST['ClientName'],
'AssignedTo' => $_POST['AssignedTo'],
'DueDate' => $_POST['DueDate'],
'TimeLogged' => $_POST['TimeLogged'],
'Notes' => $_POST['Notes'],
'Urgent' => $_POST['Urgent']
);
require('mysql.php');
$db = new mysql;
$db->connect('localhost', 'my_user', 'my_pass;', 'my_db');
$db->query("UPDATE `my_table` SET TaskName='" . mysql_real_escape_string($data['TaskName']) . "',
ClientName='" . mysql_real_escape_string($data['ClientName']) . "',
AssignedTo='" . mysql_real_escape_string($data['AssignedTo']) . "',
DueDate='" . mysql_real_escape_string($data['DueDate']) . "',
TimeLogged='" . mysql_real_escape_string($data['TimeLogged']) . "',
Notes='" . mysql_real_escape_string($data['Notes']) . "',
Urgent='" . mysql_real_escape_string($data['Urgent']) . "' WHERE id='" . mysql_real_escape_string($data['id']) . "'
");
header('Location:saved.htm');
我的形式看起來像這樣(視圖task.php)
<?php
$id = $_GET['id'];
require('mysql2.php');
$db = new mysql;
$db->connect('localhost', 'my_user', 'my_pass;', 'my_db');
$query = $db->query("SELECT * FROM `table_name` WHERE id = '" . $id ."'");
while($result = $db->fetch_array($query)) {
$data = $result;
}
?>
<form action="update-task.php" method="post" id="form1" name="form1">
<label>Task Name:</label>
<input name="TaskName" type="text" id="TaskName" size="30" value="<?php echo $data['TaskName']?>"/>
<label>Client</label>
<input name="ClientName" type="text" id="ClientName" size="30" value="<?php echo $data['ClientName']?>"/>
<label>Assigned To</label>
<input name="AssignedTo" type="text" id="AssignedTo" size="30" value="<?php echo $data['AssignedTo']?>"/>
<label>Due Date</label>
<input name="DueDate" type="text" id="DueDate" size="30" value="<?php echo $data['DueDate']?>"/>
<label>Time Logged</label>
<input type="button" value="Start Count" onClick="timedCount()">
<input type="text" value="<?php echo $data['TimeLogged']?>" id="TimeLogged" name="TimeLogged">
<input type="button" value="Stop Count" onClick="stopCount()">
<input type="button" value="Clear Timer" onClick="clearTimer()">
<label>Notes</label>
<input name="Notes" type="textarea" id="Notes" size="30" value="<?php echo $data['Notes']?>"/>
<label>Urgent</label>
<input name="Urgent" type="text" id="Urgent" size="30" value="<?php echo $data['Urgent']?>"/>
<input type="submit" value="Update" class="AddButton">
</form>
mysql.php
<?php
class mysql {
var $querynum = 0;
var $querylist = '';
function connect($dbhost, $dbuser, $dbpw, $dbname, $pconnect=0) {
$die = false;
if($pconnect) {
@mysql_pconnect($dbhost, $dbuser, $dbpw) or ($die = true);
} else {
@mysql_connect($dbhost, $dbuser, $dbpw) or ($die = true);
}
if($die) {
die(mysql_error());
}
mysql_select_db($dbname) or die(mysql_error());
}
function fetch_array($query, $type=MYSQL_ASSOC) {
$query = mysql_fetch_array($query, $type);
return $query;
}
function query($sql) {
$query = mysql_query($sql) or die(mysql_error());
$this->querynum++;
$this->querylist .= "$sql <br />";
return $query;
}
function result($query, $row) {
$query = mysql_result($query, $row);
return $query;
}
function num_rows($query) {
$query = mysql_num_rows($query);
return $query;
}
function insert_id() {
$id = mysql_insert_id();
return $id;
}
function fetch_row($query) {
$query = mysql_fetch_row($query);
return $query;
}
function affected_rows() {
$query = mysql_affected_rows();
return $query;
}
function close() {
mysql_close();
}
}
?>
Call類爲'$ DB =新的MySQL();'< - – Saty
@Saty我試過,但仍然得到錯誤「您在你的SQL語法中有一個錯誤;查看與你的MySQL服務器版本相對應的手冊,在'VALUES(0,'任務2','客戶端測試','人','04/14/2017' ','0','第一行'在第一行「 – josefresco
瞭解準備好的語句以防止sql注入,並且使語句更具可讀性 – Jens