2012-11-15 28 views
1

编辑:更新!第一部分工作。但是,我不确定如何在同一个IF()语句中检查其他变量。任何人都可以帮助我吗?单个if语句将拒绝与输入完全相同的类。但是,我需要它也拒绝平等的天和时代。只检查第一条记录,而不是全部

 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" 
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> 
<html xmlns="http://www.w3.org/1999/xhtml"> 
<head> 
<title>Register Diver</title> 
<link rel="stylesheet" href="php_styles.css" type="text/css" /> 
<meta http-equiv="content-type" 
content="text/html; charset=iso-8859-1" /> 
</head> 
<body> 
<h1>Aqua Don's Scuba School</h1> 
<h2>Registration Confirmation</h2> 
<?php 
$DiverID = $_GET['diverID']; 
if (empty($DiverID)) 
    exit("<p>You must enter a diver ID! Click your browser's Back button to return to the previous page.</p>"); 
$DBConnect = @mysqli_connect("localhost", "students", "password") 
    Or die("<p>Unable to connect to the database server.</p>" 
    . "<p>Error code " . mysqli_connect_errno() 
    . ": " . mysqli_connect_error()) . "</p>"; 
$DBName = "scuba_school"; 
@mysqli_select_db($DBConnect, $DBName) 
    Or die("<p>Unable to select the database.</p>" 
    . "<p>Error code " . mysqli_errno($DBConnect) 
    . ": " . mysqli_error($DBConnect)) . "</p>"; 

$TableName = "registration"; 
$SQLstring = "SELECT * FROM $TableName"; 
$QueryResult = @mysqli_query($DBConnect, $SQLstring); 
if (!$QueryResult) { 
    $SQLstring = "CREATE TABLE registration (diverID SMALLINT, class VARCHAR(40), days VARCHAR(40), time VARCHAR(40))"; 
    $QueryResult = @mysqli_query($DBConnect, $SQLstring) 
     Or die("<p>Unable to create the registration table.</p>" 
     . "<p>Error code " . mysqli_errno($DBConnect) 
     . ": " . mysqli_error($DBConnect)) . "</p>"; 
    echo "<p>Successfully created the registration table.</p>"; 
} 
?> 

<?php 
$Class = $_GET['class']; 
$Days = $_GET['days']; 
$Time = $_GET['time']; 
$DiverID = $_GET['diverID']; 

$DBConnect = mysqli_connect("localhost", "students", "password"); 
$DBName = "scuba_school"; 
@mysqli_select_db($DBConnect, $DBName) 
    Or die("<p>Unable to select the database.</p>" 
    . "<p>Error code " . mysqli_errno($DBConnect) 
    . ": " . mysqli_error($DBConnect)) . "</p>"; 


$sqlString= "SELECT * FROM `registration` WHERE `diverID` = $DiverID AND `class` = '$Class' AND `days` = '$Days' AND `time` = '$Time'"; 
$QueryResult = mysqli_query($DBConnect, $sqlString) or die("MySQL error: " . mysqli_error($DBConnect) . "<hr>\nQuery: $QueryResult"); 
$row = mysqli_fetch_assoc($QueryResult); 

if ($row["class"] == $Class) 
{ 

echo "<p>You are already registered for $Class</p>"; 
    } 

    elseif($row["days"] == $Days && $row["time"] == $Time) 
    { 
     echo "<p>There is a conflict with $Days or $Time</p>"; 
     } 
else 
{ 
$SQLstring = "INSERT INTO $TableName VALUES('$DiverID', '$Class', '$Days', '$Time')"; 
    $QueryResult = @mysqli_query($DBConnect, $SQLstring); 
    echo "<p>You are registered for $Class on $Days, $Time. Click your browser's Back button to register for another course or review your schedule.</p>"; 
} 


mysqli_close($DBConnect); 
?> 

</body> 
</html> 

回答

0

使用查询,说“找每个人都具有这些细节”,然后你说:“如果发现有人=坏,否则=好。例如:

SELECT ID FROM $TableName WHERE DiverID = '$DiverId', class = '$class', days='$Days' LIMIT 1 

然后你运行该查询,如果发现任何东西(if(count($results) > 0)...),那么你显示错误(或其他),如果它发现没有人则可以安全添加细节

奖金: 作为一个侧面说明,请看PDO(mysql_*个功能在PHP-土地no longer supported),并确保你过滤和净化你的投入,他们进入数据库查询之前(谷歌的是,)

0

查询后,您的情况是不好的

//change this 
if ($row['class'] == "$Class") 
{ 
    echo "<p>You are already registered for $Class</p>"; 
} 

//to this 
if(!empty($row)) 
{ 
    if ($row['class'] == "$Class") 
     echo "<p>You are already registered for $Class</p>"; 
} 
0

你的问题所在在这里:

SELECT * FROM $TableName WHERE `diverID` = $DiverID 

你查询数据库所有记录匹配diverID,忽略class。这意味着,例如,如果某个潜水员被注册到不同的类别,该查询可能会或可能不会检索到该记录。你想somethingl IKE:

// this is for simplicity's sake only; please escape your input in your code!! 

$sql = "SELECT * FROM $TableName WHERE `diverID` = $DiverID AND `class` = '$Class'" 
$query = mysqli_query($sql); 

if (mysqli_num_rows($query)) { 
    // already registered 
} else { 
    // not registered, insert 
} 

话虽这么说...

  1. 不要使用@(错误抑制)。关闭生产中的错误报告,但这(抑制错误)是可怕的。

  2. 不要让您的代码容易受到SQL injection的影响。你甚至没有试图逃脱任何东西,更糟,你使用的是$_GET,这也让你容易受到CSRF攻击。

  3. 不要动态创建表格。在脚本执行之前,您应该已经准备好了表结构。如果有的话,它们应该由安装脚本创建。

+0

问题是我需要为3个变量做这个。一级是我认为最简单的。如果我做了一个i ++或其他什么东西去下每行呢?我不擅长编码......这是为了上课,所以我试图摆脱老师提供的例子,但没有这方面的例子。 – Tandar

+0

我已更新我的代码,但无法弄清楚如何让其他部分工作。你可以看一下吗? – Tandar

相关问题