尝试传递GET
变量时,我遇到了一个奇怪的错误。在产品页面上,我对同一产品有多种尺寸,每种尺寸都有自己的形式,包含两个变量product ID (product_id)
和quantity (qty)
,它们被发送到另一个页面(add.php)以添加到购物车。
我的问题是qty
没有问题但product_id
没有通过,我使用Burp套件检查服务器和客户端之间发送的数据,当我点击提交按钮时product_id
没有附加到网址上(我们可以在下面看到)
获取/newsite/add.php?qty=1 HTTP / 1.1
这是我使用的代码
$selectQuery = "SELECT * FROM products WHERE product_master_id = $masterID ORDER BY length(product_quantity_description), product_quantity_description";
$selectResult = mysql_query($selectQuery);
$i = 0;
while($selectRow = mysql_fetch_array($selectResult)) {
echo '<form action="add.php?product_id='.$selectRow['product_id'].'&qty=<script>document.getElementById(\'qty'.$i.'\').value</script>" class="form form-inline clearfix">
<span class="tag" id="desc">'.$selectRow['product_name'].'</span>
<span class="tag" id="qtyDesc">$'.$selectRow['product_quantity_description'].'</span>
<span class="tag" id="oldPrice">$'.number_format ($selectRow['old_price'], 2).'</span>
<span class="tag" id="averagePrice">$'.number_format ($selectRow['average_price'], 2).'</span>
<span class="tag" id="price">$'.number_format ($selectRow['product_price'], 2).'</span>
<div class="numbered">
<input type="text" name="qty" id="qty'.$i.'" value="1" class="tiny-size" />
<span class="clickable add-one icon-plus-sign-alt"></span>
<span class="clickable remove-one icon-minus-sign-alt"></span>
</div>';
if($selectRow['Special'] == 1 && $selectRow['product_oos'] == 0)
echo '<span class="stock">
<span class="btn btn-warning" id="stock">Ask for availability</span>
</span>';
if($selectRow['product_oos'] == 1)
echo '<span class="btn btn-danger pull-right">Out of Stock</span>';
else
echo '<button class="btn btn-success pull-right">Add <i class="icon-shopping-cart"></i></button>';
echo '</form>';
$i++;
}
通过查看加载页面的源代码,我们可以看到这一点
<form action="add.php?product_id=559&qty=<script>document.getElementById('qty0').value</script>" class="form form-inline clearfix">
我不明白为什么qty
被附加到网址而不是product_id
。
答案 0 :(得分:2)
在这种情况下,您必须在隐藏字段中传递变量。不要让简单的事情变得复杂。
<input type="hidden" name="product_id" value="$selectRow['product_id']" />
<input type="hidden" name="qty" value="document.getElementById(\'qty'.$i.'\').value" />
并制作
<input type="text" name="qty" id="qty'.$i.'" value="1" class="tiny-size" />
到
<input type="text" id="qty'.$i.'" value="1" class="tiny-size" />
现在您的代码看起来像。
$selectQuery = "SELECT * FROM products WHERE product_master_id = $masterID ORDER BY length(product_quantity_description), product_quantity_description";
$selectResult = mysql_query($selectQuery);
$i = 0;
while($selectRow = mysql_fetch_array($selectResult)) {
echo '<form action="add.php" class="form form-inline clearfix">
<span class="tag" id="desc">'.$selectRow['product_name'].'</span>
<span class="tag" id="qtyDesc">$'.$selectRow['product_quantity_description'].'</span>
<span class="tag" id="oldPrice">$'.number_format ($selectRow['old_price'], 2).'</span>
<span class="tag" id="averagePrice">$'.number_format ($selectRow['average_price'], 2).'</span>
<span class="tag" id="price">$'.number_format ($selectRow['product_price'], 2).'</span>
<div class="numbered">
<input type="hidden" name="product_id" value="$selectRow['product_id']" />
<input type="hidden" name="qty" value="document.getElementById(\'qty'.$i.'\').value" />
<input type="text" id="qty'.$i.'" value="1" class="tiny-size" />
<span class="clickable add-one icon-plus-sign-alt"></span>
<span class="clickable remove-one icon-minus-sign-alt"></span>
</div>';
if($selectRow['Special'] == 1 && $selectRow['product_oos'] == 0)
echo '<span class="stock">
<span class="btn btn-warning" id="stock">Ask for availability</span>
</span>';
if($selectRow['product_oos'] == 1)
echo '<span class="btn btn-danger pull-right">Out of Stock</span>';
else
echo '<button class="btn btn-success pull-right">Add <i class="icon-shopping-cart"></i></button>';
echo '</form>';
$i++;
}