ajax的问题​​,只显示标题而不是记录

时间:2018-05-31 07:57:27

标签: php ajax

我的代码有问题。

我创建了一个直接从数据库中获取类别的下拉菜单。到目前为止一切都很好。 但是,当我选择类型时,它只显示表格的标题而不显示记录。 你能告诉我为什么吗?

我认为问题是" q"但我不知道如何修改它因为我试图在没有' Where'并正确显示记录。

<html>
<script>
var xmlhttp;

function mostraInfo(str)
{


xmlhttp=GetXmlHttpObject();
if (xmlhttp==null)
{
alert ("Browser does not support HTTP Request");
return;
}

var url="2.php";
url=url+"?q="+str;
xmlhttp.onreadystatechange=stateChanged;
xmlhttp.open("GET",url,true);
xmlhttp.send(null);
}

function stateChanged()
{
if (xmlhttp.readyState==4)
{
document.getElementById("info").innerHTML=xmlhttp.responseText;
}
}

function GetXmlHttpObject()
{
if (window.XMLHttpRequest) 
{
// code for IE7+, Firefox, Chrome, Opera, Safari
return new XMLHttpRequest();
}
if (window.ActiveXObject)
{
// code for IE6, IE5
return new ActiveXObject("Microsoft.XMLHTTP"); 
}
return null;
}
</script>

<form>
Seleziona Categoria:
<select name="users" onChange="mostraInfo(this.value)">
<option value="">Seleziona categoria:</option>
<?php 
//Seleziono quelli che sono i dipendenti
$dbhost="localhost";
$dbname="my_lisipcivicsense";
$dbuser="lisipcivicsense";
$dbpsw="";

$con = mysql_connect($dbhost, $dbname, $dbpsw);
mysql_select_db($dbname, $con);
$query = "SELECT distinct tipologia FROM gruppi ORDER BY tipologia ASC";
$result = mysql_query($query);
while($riga = mysql_fetch_array($result)){
echo "<option value='$riga[nome_gruppo]'> $riga[tipologia] </option>";
}
?>
</select>
</form>
<br />
<div id="info"></div>
</html>

-----文件2(2.php)------     

$dbhost="localhost";
$dbname="my_lisipcivicsense";
$dbuser="lisipcivicsense";
$dbpsw="";

$con = mysql_connect($dbhost, $dbname, $dbpsw);
mysql_select_db($dbname, $con);

$sql="SELECT * FROM gruppi  WHERE tipologia = '".$q."'" ;

$result = mysql_query($sql);

echo "<table border='2'>
<tr>
<th> Nome Gruppo </th>
<th> Email </th>
<th> Tipologia </th>
</tr>";

while($row = mysql_fetch_array($result))
{
echo "<tr>";
echo "<td>" . $row['nome_gruppo'] . "</td>";
echo "<td>" . $row['email_gruppo'] . "</td>";
echo "<td>" . $row['tipologia'] . "</td>";
echo "</tr>";
}
echo "</table>";

mysql_close($con);

?>

2 个答案:

答案 0 :(得分:0)

看来你的问题是查询,你在单引号内使用双引号,试试这个:

$sql="SELECT * FROM gruppi  WHERE tipologia = '{$q}'" ;

答案 1 :(得分:0)

根据您提供的代码,我不知道$ q定义在哪里。 所以我相信你的查询结果如下:

"SELECT * FROM gruppi  WHERE tipologia = ''"

你总是可以通过插入像这样的临时代码来转储某些内容以检查实际情况:

var_dump($sql);exit;

请勿在调试后忘记删除/评论;)

解决方案:

你需要得到&#34; q&#34;来自GET请求的参数:

$q = mysql_real_escape_string($_GET['q'], $con);
$sql="SELECT * FROM gruppi  WHERE tipologia = '".$q."'" ;

mysql_real_escape_string 函数可以防止一些简单的SQL注入。请查看http://php.net/manual/en/function.mysql-real-escape-string.php

但最好至少使用PDO class而不是过时的&#34; mysql _&#34;功能

2.php的完整代码,修复:

$dbhost="localhost";
$dbname="my_lisipcivicsense";
$dbuser="lisipcivicsense";
$dbpsw="";

$con = mysql_connect($dbhost, $dbname, $dbpsw);
mysql_select_db($dbname, $con);

$q = mysql_real_escape_string($_GET['q'], $con);
$sql="SELECT * FROM gruppi  WHERE tipologia = '".$q."'" ;

$result = mysql_query($sql);

echo "<table border='2'>
<tr>
<th> Nome Gruppo </th>
<th> Email </th>
<th> Tipologia </th>
</tr>";

while($row = mysql_fetch_array($result))
{
echo "<tr>";
echo "<td>" . $row['nome_gruppo'] . "</td>";
echo "<td>" . $row['email_gruppo'] . "</td>";
echo "<td>" . $row['tipologia'] . "</td>";
echo "</tr>";
}
echo "</table>";

mysql_close($con);

?>