2012-05-30 139 views
0

我想将亚马逊API集成到我的网站,到目前为止我已经设法让它导航到正确的XML部分和存储作为一个变量,但我现在试图插入这个varibable到我的mysql数据库而它给我这个错误未定义的变量错误

注意:未定义的变量:sql_select中在 致命错误:调用一个成员函数查询()非对象

什么我做错了吗?

整个代码

define('INCLUDED', 1); 
error_reporting(E_ALL); 
ini_set("display_errors", 1); 
$AWS_ACCESS_KEY_ID = "HIDDENFORPRIVACY"; 
$AWS_SECRET_ACCESS_KEY = "HIDDENFORPRIVACY"; 

$base_url = "http://free.apisigning.com/onca/xml?"; 
$url_params = array('Operation'=>"ItemLookup",'Service'=>"AWSECommerceService", 
'AWSAccessKeyId'=>$AWS_ACCESS_KEY_ID,'AssociateTag'=>"HIDDENFORPRIVACY", 
'Version'=>"2011-08-01",'Availability'=>"Available",'ItemId'=>"0273702440", 
'ItemPage'=>"1",'ResponseGroup'=>"EditorialReview", 'Title'=>"Accounting and Finance for Non-Specialists 5th Edition"); 

// Add the Timestamp 
$url_params['Timestamp'] = gmdate("Y-m-d\TH:i:s.\\0\\0\\0\\Z", time()); 

// Sort the URL parameters 
$url_parts = array(); 
foreach(array_keys($url_params) as $key) 
    $url_parts[] = $key."=".$url_params[$key]; 
sort($url_parts); 

// Construct the string to sign 
//$string_to_sign = "GET\nhttp://free.apisigning.com/".implode("&",$url_parts); 
//$string_to_sign = str_replace('+','%20',$string_to_sign); 
//$string_to_sign = str_replace(':','%3A',$string_to_sign); 
//$string_to_sign = str_replace(';',urlencode(';'),$string_to_sign); 

// Sign the request 
//$signature = hash_hmac("sha256",$string_to_sign,$AWS_SECRET_ACCESS_KEY,TRUE); 

// Base64 encode the signature and make it URL safe 
//$signature = base64_encode($signature); 
//$signature = str_replace('+','%2B',$signature); 
//$signature = str_replace('=','%3D',$signature); 
//$signature = str_replace(';',urlencode(';'),$string_to_sign); 
$url_string = implode("&",$url_parts); 
$url = $base_url.$url_string; 
//print $url; 


$ch = curl_init();     //this part we set up curl 
curl_setopt($ch, CURLOPT_URL,$url); 
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); 
curl_setopt($ch, CURLOPT_TIMEOUT, 15); 
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); 
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); 
$xml_response = curl_exec($ch); 
curl_close($ch); 
header('Content-type: application/xml'); //specify as xml to not display as one long string 
echo $xml_response; 

$xml = new SimpleXMLElement($xml_response); //time to echo back the correct piece of data 

$editorialReview = $xml->Items->Item->EditorialReviews->EditorialReview->Content; 

$variable = '<p>Editorial review: '.html_entity_decode($editorialReview).'</p>'."\n"; 
echo $variable; 

$sql_select = mysql_query("INSERT INTO " . DB_PREFIX . "auctions 
      (amazon_description) VALUES 
      ('" . $variable . "')"); 
      echo ($sql_select); 

这不发送错误,但MySQL数据库显示没有变化

+1

什么是$ sql_select?它来自哪里?你的代码没有显示。 –

+0

试试这个:$ sql_select-> query(“INSERT INTO {DB_PREFIX} auctions(amazon_description)VALUES('{$ variable}')”); – B4NZ41

+0

尼斯[SQL注入](http://bobby-tables.com)洞... –

回答

1

错误“未定义变量”表示你还没有初始化的对象。

从您打印的代码看来,$ sql_select 应该是是一个具有select语句的字符串。

所以,你需要做的是这样的:

$variable = '<p>Editorial review: '.html_entity_decode($editorialReview).'</p>'."\n"; 
echo $variable; 

$sql_select .= "INSERT INTO " . DB_PREFIX . "auctions 
      (amazon_description) VALUES 
      ('" . $variable . "')"; 

$DB_object->query($sql_select); 

请张贴整个代码,使该解决方案可以准确地发现了。

+0

为什么'。='帮助这里? – Ben

+0

因为我不确定整个代码,并且可能有预先的SQL注释并且暗示其他先前的SQL语句要批量执行。 –

+0

@JackBrown我已编辑我的帖子,包括整个代码,当前的代码不会产生错误,但mysql数据库不会正确更新 –