GET参数不通过

时间:2014-06-26 05:59:35

标签: javascript php get

尝试传递GET变量时,我遇到了一个奇怪的错误。在产品页面上,我对同一产品有多种尺寸,每种尺寸都有自己的形式,包含两个变量product ID (product_id)quantity (qty),它们被发送到另一个页面(add.php)以添加到购物车。

我的问题是qty没有问题但product_id没有通过,我使用Burp套件检查服务器和客户端之间发送的数据,当我点击提交按钮时product_id没有附加到网址上(我们可以在下面看到)

  

获取/newsite/add.php?qty=1 HTTP / 1.1

这是我使用的代码

$selectQuery = "SELECT * FROM products WHERE product_master_id = $masterID ORDER BY length(product_quantity_description), product_quantity_description";
$selectResult = mysql_query($selectQuery);
$i = 0;
while($selectRow = mysql_fetch_array($selectResult)) {
    echo '<form action="add.php?product_id='.$selectRow['product_id'].'&qty=<script>document.getElementById(\'qty'.$i.'\').value</script>" class="form form-inline clearfix">
    <span class="tag" id="desc">'.$selectRow['product_name'].'</span>                                   
    <span class="tag" id="qtyDesc">$'.$selectRow['product_quantity_description'].'</span>
    <span class="tag" id="oldPrice">$'.number_format ($selectRow['old_price'], 2).'</span>
    <span class="tag" id="averagePrice">$'.number_format ($selectRow['average_price'], 2).'</span>
    <span class="tag" id="price">$'.number_format ($selectRow['product_price'], 2).'</span>
    &nbsp;
    <div class="numbered">
        <input type="text" name="qty" id="qty'.$i.'" value="1" class="tiny-size" />
        <span class="clickable add-one icon-plus-sign-alt"></span>
        <span class="clickable remove-one icon-minus-sign-alt"></span>
    </div>';
    if($selectRow['Special'] == 1 && $selectRow['product_oos'] == 0)
        echo '<span class="stock">
            <span class="btn btn-warning" id="stock">Ask for availability</span>
            </span>';
    if($selectRow['product_oos'] == 1)
        echo '<span class="btn btn-danger pull-right">Out of Stock</span>';
    else
        echo '<button class="btn btn-success pull-right">Add &nbsp; <i class="icon-shopping-cart"></i></button>';
    echo '</form>';
    $i++;
}

通过查看加载页面的源代码,我们可以看到这一点

<form action="add.php?product_id=559&amp;qty=&lt;script&gt;document.getElementById('qty0').value&lt;/script&gt;" class="form form-inline clearfix">

我不明白为什么qty被附加到网址而不是product_id

1 个答案:

答案 0 :(得分:2)

在这种情况下,您必须在隐藏字段中传递变量。不要让简单的事情变得复杂。

<input type="hidden" name="product_id" value="$selectRow['product_id']" />
<input type="hidden" name="qty" value="document.getElementById(\'qty'.$i.'\').value" />

并制作

<input type="text" name="qty"  id="qty'.$i.'" value="1" class="tiny-size" />


<input type="text"  id="qty'.$i.'" value="1" class="tiny-size" />

现在您的代码看起来像。

$selectQuery = "SELECT * FROM products WHERE product_master_id = $masterID ORDER BY     length(product_quantity_description), product_quantity_description";
$selectResult = mysql_query($selectQuery);
$i = 0;
while($selectRow = mysql_fetch_array($selectResult)) {
echo '<form action="add.php" class="form form-inline clearfix">
<span class="tag" id="desc">'.$selectRow['product_name'].'</span>                                   
<span class="tag" id="qtyDesc">$'.$selectRow['product_quantity_description'].'</span>
<span class="tag" id="oldPrice">$'.number_format ($selectRow['old_price'], 2).'</span>
<span class="tag" id="averagePrice">$'.number_format ($selectRow['average_price'], 2).'</span>
<span class="tag" id="price">$'.number_format ($selectRow['product_price'], 2).'</span>
&nbsp;
<div class="numbered">
<input type="hidden" name="product_id" value="$selectRow['product_id']" />
<input type="hidden" name="qty" value="document.getElementById(\'qty'.$i.'\').value" />       
<input type="text"  id="qty'.$i.'" value="1" class="tiny-size" />
    <span class="clickable add-one icon-plus-sign-alt"></span>
    <span class="clickable remove-one icon-minus-sign-alt"></span>
</div>';
if($selectRow['Special'] == 1 && $selectRow['product_oos'] == 0)
    echo '<span class="stock">
        <span class="btn btn-warning" id="stock">Ask for availability</span>
        </span>';
if($selectRow['product_oos'] == 1)
    echo '<span class="btn btn-danger pull-right">Out of Stock</span>';
else
    echo '<button class="btn btn-success pull-right">Add &nbsp; <i class="icon-shopping-cart"></i></button>';
echo '</form>';
$i++;

}