提交影响超过其应该行的行的按钮

时间:2015-05-13 12:51:54

标签: php mysql forms

所以我已经完成了所有工作,但由于某种原因,每列中的按钮会影响该列中的所有行。因此,例如,如果我在数据库中有3条记录,并且我单击CallAttemptOne(第3行)中的按钮,它将影响行1,2,3。我在这做错了什么?感谢

(也是的,我意识到代码已被弃用。那是第二步!)

//superfluous code removed

$table = 'Project_Submissions';

if (!mysql_connect($db_host, $db_user, $db_pwd))
    die("Can't connect to database");
if (!mysql_select_db($database))
    die("Can't select database");

//Display all fields
$result = mysql_query("SELECT * FROM {$table} ORDER BY ID DESC");

//superfluous code removed


while ($row = mysql_fetch_array($result)) 
{
    echo "<tr>
    <td style='font-size:12px;'><center>{$row['ID']}</center></td>
    <td style='font-size:12px;'>{$row['First_Name']} {$row['Last_Name']}</td>
    <td style='font-size:12px;'><center>";

    //-------------------------------------------------
    if(empty($row['CallAttemptOne']))
    {
    echo" 
        <form action='".$_SERVER['PHP_SELF']."' method='post'>
        <input type='hidden' id='ID' name='ID' value='{$row['ID']}' />
        <input type='submit' name='formCalledOne' id='formCalledOne' value='Called' />
        </form>
        {$row['CallAttemptOne']}";
    }
    else
    {
    echo "{$row['CallAttemptOne']}";
    }


    echo "</center></td><td style='font-size:12px;'><center>";

    //-------------------------------------------------
    if(empty($row['CallAttemptTwo']))
    {
    echo" 
        <form action='".$_SERVER['PHP_SELF']."' method='post'>
        <input type='hidden' id='ID' name='ID' value='{$row['ID']}' />
        <input type='submit' name='formCalledTwo' id='formCalledTwo' value='Called' />
        </form>
        {$row['CallAttemptTwo']}";
    }
    else
    {
    echo "{$row['CallAttemptTwo']}";
    }


    echo "</center></td><td style='font-size:12px;'><center>";

    //-------------------------------------------------
    if(empty($row['CallAttemptThree']))
    {
    echo" 
        <form action='".$_SERVER['PHP_SELF']."' method='post'>
        <input type='hidden' id='ID' name='ID' value='{$row['ID']}' />
        <input type='submit' name='formCalledThree' id='formCalledThree' value='Called' />
        </form>
        {$row['CallAttemptThree']}";
    }
    else
    {
    echo "{$row['CallAttemptThree']}";
    }


    echo "</center></td><td style='font-size:12px;'><center>";

    //-------------------------------------------------
    if(empty($row['EmailAttempt']))
    {
    echo" 
        <form action='".$_SERVER['PHP_SELF']."' method='post'>
        <input type='hidden' id='ID' name='ID' value='{$row['ID']}' />
        <input type='submit' name='formEmailAttempt' id='formEmailAttempt' value='Emailed' />
        </form>
        {$row['EmailAttempt']}";
    }
    else
    {
    echo "{$row['EmailAttempt']}";
    }


    echo "</center></td>

    //-------------------------------------------------
    <td style='font-size:12px;'><center>Text Area</center></td>
    <td style='font-size:12px;'><center>{$row['Received_Date']}</center></td>
    <td style='font-size:12px;'><center>

        <form action='".$_SERVER['PHP_SELF']."' method='post'>
        <input type='hidden' id='ID' name='ID' value='{$row['ID']}' />
        <input type='submit' name='formDelete' id='formDelete' value='Delete' />
        </form>


    </center></td>
    </tr>";

}
    //-------------------------------------------------
    //Check to see if delete button is pressed
    if(isset($_POST['formDelete']))
    {
        if(isset($_POST['ID']) && !empty($_POST['ID']))
        {
            $deleteID = $_POST['ID'];
            $result = mysql_query("DELETE FROM Project_Submissions WHERE ID ='".$deleteID."'");
        }
    }   
    //-------------------------------------------------
    if(isset($_POST['formCalledOne']))//Check to see if Call Attempt One button is pressed
    {
        if(isset($_POST['ID']) && !empty($_POST['ID']))
        {
            $callattemptoneID = $_POST['ID'];
            $callattemptonequery = mysql_query("UPDATE Project_Submissions SET CallAttemptOne=CURDATE() WHERE ID ='".$callattemptoneID."' AND CallAttemptOne IS NULL OR LENGTH(CallAttemptOne)=0");
        }
    }   
    //-------------------------------------------------
    if(isset($_POST['formCalledTwo']))//Check to see if Call Attempt Two button is pressed
    {
        if(isset($_POST['ID']) && !empty($_POST['ID']))
        {
            $callattempttwoID = $_POST['ID'];
            $callattempttwoquery = mysql_query("UPDATE Project_Submissions SET CallAttemptTwo=CURDATE() WHERE ID ='".$callattempttwoID."' AND CallAttemptTwo IS NULL OR LENGTH(CallAttemptTwo)=0");
        }
    }   
    //-------------------------------------------------
    if(isset($_POST['formCalledThree']))//Check to see if Call Attempt Three button is pressed
    {
        if(isset($_POST['ID']) && !empty($_POST['ID']))
        {
            $callattemptthreeID = $_POST['ID'];
            $callattemptthreequery = mysql_query("UPDATE Project_Submissions SET CallAttemptThree=CURDATE() WHERE ID ='".$callattemptthreeID."' AND CallAttemptThree IS NULL OR LENGTH(CallAttemptThree)=0");
        }
    }   
    //-------------------------------------------------
    if(isset($_POST['formEmailAttempt']))//Check to see if Email Attempt button is pressed
    {
        if(isset($_POST['ID']) && !empty($_POST['ID']))
        {
            $emailattemptID = $_POST['ID'];
            $emailattemptquery = mysql_query("UPDATE Project_Submissions SET EmailAttempt=CURDATE() WHERE ID ='".$emailattemptID."' AND EmailAttempt IS NULL OR LENGTH(EmailAttempt)=0");
        }
    }   
?>
</body>
</html>

1 个答案:

答案 0 :(得分:1)

尝试在查询中使用括号:

UPDATE Project_Submissions SET EmailAttempt=CURDATE() WHERE ID ='".$emailattemptID."' AND (EmailAttempt IS NULL OR LENGTH(EmailAttempt)=0);

您的查询之前无法工作的原因是WHERE部分中逻辑运算符的优先顺序。逻辑从左到右执行,所以基本上你的查询与

相同
SELECT WHERE (ID ='".$emailattemptID."' AND EmailAttempt IS NULL) OR LENGTH(EmailAttempt)=0;

因此LENGTH(EmailAttempt)=0为真的每一行都包含在结果中。除了将OR部分括在括号中之外,您还可以颠倒顺序:

SELECT WHERE EmailAttempt IS NULL OR LENGTH(EmailAttempt)=0 AND ID ='".$emailattemptID."';

但除此之外,正如前面的评论中所提到的,你不应该直接在查询中使用变量,因为这会使你的代码对SQL注入攻击开放。