分页我的博客不起作用

时间:2015-02-17 22:21:51

标签: php mysql pagination

我正在尝试使用PHP,HTML和MySQL创建一个分页博客。我写了代码,但由于某种原因,网页显示空白。我的代码出了什么问题? Chrome控制台会返回500内部服务器错误。

<div id="article">

<?php
  include 'php/mysql_connect.php';
  if(empty($_GET)){
    $current_id = SELECT max(id) FROM posts;
  }
  else{
    $current_id = mysql_safe_string($_GET['id']);
  }

  $result = mysql_safe_query('SELECT * FROM posts WHERE id=%s LIMIT 1',$current_id);
  if(!mysql_num_rows($result)){
    echo '<h2>No Posts Found</h2>';
    exit;
  }

  $row = mysql_fetch_assoc($result)
  echo '<h2>'.$row['title'].'</h2>';
  echo '<div class="row">';
  echo '  <div class="group1 col-sm-6 col-md-6">';
  echo '    <span class="glyphicon glyphicon-pencil"></span><a data-toggle="collapse" data-target="#comments" class"collapsed">'.$row['num_comments'].' Comments </a>';
  echo '    <span class="glyphicon glyphicon-time"></span>'.date('F j<\s\up>S</\s\up>, Y', $row['date']);
  echo '  </div>';
  echo '</div>';
  echo '<br />';
  echo '<p class="lead">'.n12br($row['body']).'</p>';
  ?> 

  <div id="comments" class="collapse" >
    <div class="well">
      <h4>Leave a comment</h4>
      <?php echo '<form role="form" method="post" action="php/comment_add.php?id=($current_id)" class="clearfix">'; ?>
        <div class="col-md-6 form-group">
          <label class="sr-only" for="name">Name</label>
          <input type="text" class="form-control" id="name" placeholder="Name" required />
        </div>
        <div class="col-md-6 form-group">
            <label class="sr-only" for="email">Email</label>
            <input type="email" class="form-control" id="email" placeholder="Email" required />
       </div>
        <div class="col-md-12 form-group">
            <label class="sr-only" for="content">Comment</label>
            <textarea class="form-control" id="content" placeholder="Comment" required></textarea>
        </div>
        <div class="col-md-12 form-group text-right">
            <button type="submit" class="btn btn-primary">Submit</button>
        </div>
      </form>
    </div>
    <br>

<?php 
  $result = mysql_safe_query('SELECT * FROM comments WHERE post_id=%s ORDER BY date ASC',$current_id);
  echo '  <ul id="comments" class="comments">';

  while($row = mysql_fetch_assoc($result)){
  echo '    <li class="comment">';
  echo '      <div id="inline" ><h4 style="display:inline;">'.$row['name'].'</h1><sup><p style="display:inline; font-size:10px;">&nbsp; '.date('j-M-Y g:ia', $row['date']).'</p></sup></div>';
  echo '      <em>'.n12br($row['content']).'</em>';
  echo '    </li>';
  echo '  </ul>';
  }
?>
    <hr>
  </div>
</div>

<nav>
  <ul class="pager">
<?php

    $newer_id = IFNULL(mysql_safe_query('SELECT min(id) FROM posts WHERE id > $current_id ORDER BY id ASC LIMIT 1'),-1);
    $older_id = IFNULL (mysql_safe_query('SELECT max(id) FROM posts WHERE id < $current_id ORDER BY id ASC LIMIT 1'),-1);

    if($newer_id != -1){
      echo '<li><a href="#">Newer</a></li>';
    }
    if ($older_id != -1){
      echo '<li><a href="#">Older</a></li>';
    }
?>
  </ul>
</nav>

这是php / mysql_connect.php,它应该阻止sql注入(我从教程中得到了这个):

<?php
// mysql.php
function mysql_safe_string($value) {
    $value = trim($value);
    if(empty($value))           return 'NULL';
    elseif(is_numeric($value))  return $value;
    else                        return "'".mysql_real_escape_string($value)."'";
}

function mysql_safe_query($query) {
    $args = array_slice(func_get_args(),1);
    $args = array_map('mysql_safe_string',$args);
    return mysql_query(vsprintf($query,$args));
}

function redirect($uri) {
    header('location:'.$uri);
    exit;
}

mysql_connect('localhost','(username)','(password)');
mysql_select_db('(database)');

从日志中我找到了失败:

Syntax error, unexpected 'max' (T_STRING) on line 6 (if(empty($_GET)){$current_id = SELECT max(id) FROM posts})

3 个答案:

答案 0 :(得分:1)

if(empty($_GET)){
    $current_id = SELECT max(id) FROM posts;
}

sql周围没有引号是错误的。

答案 1 :(得分:1)

正如其他人指出的那样(并且应该通过您所面临的语法错误立即清楚),您的$current_id查询未被引用。一个好的开始是修复第一个块:

if(empty($_GET)) {
    $current_id = "SELECT max(id) FROM posts;";
} else {
    $current_id = mysql_safe_string($_GET['id']);
}

答案 2 :(得分:0)

如果您的文件是myfile.html并且您没有嵌入式PHP的权限,则它将无法在服务器上执行。