用$ _GET [""]用PHP和SQL增加页面

时间:2016-05-27 20:05:58

标签: php mysql database pdo blogs

目前我正在忙于一个博客,但我不知道增加页面,抵消和限制。它应该计算页面并在按钮点击的每一页显示10行。我有这个:

    <?php

$rowsPerPage = 10; //number of results you want to display 
$num = $_GET["page"]; //set the offset to start w/the num. of results (good for paging)
$offset = ($num - 1) * $rowsPerPage; // to offset the limit count 
$sql = "SELECT * FROM `posts` ORDER BY `id` DESC LIMIT ".$rowsPerPage." OFFSET ".$offset."";
$result = $conn->query($sql);
while($row = $result->fetch(PDO::FETCH_ASSOC)) {
    echo '<div class="post-preview">
            <a href="posts.php?id='.$row["id"].'">
                <h2 class="post-title">
                    '.$row["title"].'
                </h2>
                <h3 class="post-subtitle">
                    '.$row["content"].'
                </h3>
            </a>
            <p class="post-meta"><a href="#">'.$row["creator"].'</a> | '.$row["date"].'</p>
        </div>
        <hr>';
    }       
    ?>

但它似乎只适用于domain.com/index.php?page=1,它加载正常等。当我删除&#39; /index.php?page = 1&#39;并转到没有$ _GET设置的索引我得到以下错误:

Fatal error: Uncaught exception 'PDOException' with message 'SQLSTATE[42000]: Syntax error or access violation: 1064 You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near '-10' at line 1' in /home/u9778802/public_html/blog/index.php:49 Stack trace: #0 /home/u9778802/public_html/blog/index.php(49): PDO->query('SELECT * FROM `...') #1 {main} thrown in /home/u9778802/public_html/blog/index.php on line 49

我希望有人可以帮助我。

1 个答案:

答案 0 :(得分:1)

虽然您对SQL注入持开放态度,但可以使用以下方法解决逻辑问题:

$num = (isset($_GET["page"]) and is_int($_GET["page"])) ? $_GET["page"] : 1;