如何使用表单输入验证查询记录

时间:2017-11-12 14:54:48

标签: php mysqli location

在我的代码下面我有两个表单部分,第一个是从数据库中获取信息,第二个是验证数据库中的记录我的问题是如何验证记录并重定向到错误页面或输入表单不是将我的代码中的任何记录重定向到索引页面;

<?php
include_once 'init.php';
$error = false;

//check if form is submitted
if (isset($_POST['book'])) {
    $book = mysqli_real_escape_string($conn, $_POST['book']);
    $action = mysqli_real_escape_string($conn, $_POST['action']);
    if (strlen($book) < 6) {
        $error = true;
        $book_error = "booking code must be alist 6 in digit";
    }
    if (!is_numeric($book)) {
        $error = true;
        $book_error = "Incorrect booking code";
    }
    if (empty($_POST["action"])) {
        $error = true;
        $action_error = "pick your action and try again";
    }
    if (!$error) {
        if(preg_match('/(check)/i', $action)) {
            echo "6mameja";
        } 
        if (preg_match('/(comfirm)/i', $action)) {
            if(isset($_SESSION["user_name"]) && (trim($_SESSION["user_name"]) != "")) {
                $username=$_SESSION["user_name"];
                $result=mysqli_query($conn,"select * from users where username='$username'");
            }
            if ($row = mysqli_fetch_array($result)) {
                $id = $row["id"];
                $username=$row["username"];
                $idd = $row["id"];
                $username = $row["username"];
                $ip = $row["ip"];
                $ban = $row["validated"];
                $balance = $row["balance"];
                $sql = "SELECT `item_name` , `quantity` FROM `books` WHERE `book`='$book'";
                $query = mysqli_query($conn, $sql);
                while ($rows = mysqli_fetch_assoc($query)) {
                    $da  = $rows["item_name"]; $qty  = $rows["quantity"];
                    $sqll = mysqli_query($conn, "SELECT * FROM promo WHERE code='$da' LIMIT 1");
                   while ($prow = mysqli_fetch_array($sqll)) {
                       $pid = $prow["id"];
                       $price = $prow["price"];
                       $count = 0;
                       $count = $qty * $price;
                       $show = $count + $show;
                    }
                }
                echo "$show";
                echo "$balance";
                if ($show<$balance) {
                    if (isset($_POST["verify"])) {
                        $pass = mysqli_real_escape_string($conn, $_POST["pass"]);
                        if ($pass != "$username") {
                            header("location: index.php");
                        }
                        elseif ($pass = "$username") {
                            header("location: ../error.php");
                        }
                    }
                    echo '<form action="#" method="post" name="verify"><input class="text" name="pass" type="password" size="25" /><input class="text" type="submit" name="verify" value="view"></form>';
                    echo "you cant buy here";
                    exit();
                }
            } else {
                $errormsg = "Error in registering...Please try again later!";
            }
        }
    }
}
?>

<form role="form" action="<?php echo $_SERVER['PHP_SELF']; ?>" method="post" name="booking">
    <fieldset>
        <legend>Check Booking</legend>

        <div class="form-group">
            <label for="name">Username</label>
            <input type="text" name="book" placeholder="Enter  Username" required value="<?php if($error) echo $book; ?>" class="form-control" />
            <span class="text-danger"><?php if (isset($book_error)) echo $book_error; ?></span>
        </div>
        <input type="submit" name="booking" value="Sign Up" class="btn btn-primary" />
        <table>
            <input type="radio" name="action" value="comfirm" <?php if(isset($_POST['action']) && $_POST['action']=="comfirm") { ?>checked<?php  } ?>> 
            <input type="radio" name="action" value="check" <?php if(isset($_POST['action']) && $_POST['action']=="check") { ?>checked<?php  } ?>> Check booking <span class="text-danger"><?php if (isset($action_error)) echo $action_error; ?></span>
            </div>
        </table>
    </fieldset>
</form>

在成就中我应该重定向到错误或索引页面,但我上面的代码重新回到第一次形成我做错了什么。非常感谢提前

0 个答案:

没有答案