向通过php / html脚本生成的按钮添加功能

时间:2019-02-27 06:44:45

标签: php html mysql sql mysqli

我对PHP / HTML / CSS编程非常陌生,在下面附加的代码中,我试图创建网站管理面板的基本功能。

我想要做的是打印出表及其所有行和列,并增加一列带有控件的控件,这些控件使我可以从数据库中删除该行。最终,我想为每个用户更改名称,密码和管理员特权。

此外,我真的不知道如何使每个按钮保持一个将其连接到其相应行的值。

也许是由于我是一位经验不足的程序员,所以我所有的尝试都失败了,或者删除了最后一行(也许因为它是$email变量名下的最后一个值)。一位朋友建议使用JavaScript或迁移到其他平台(他的建议是Angular JS)以实现我的目标,但到目前为止,我真的想使用PHP使其保持简单(如果确实如此)和CSS。


以下是管理面板的图像:

Click here to see an ugly administration panel.


这是我的表生成器(或者与我设法得到的一样好):

<?php
    include "connection.php"; 

    $sql = "SELECT * FROM users;";
    $result = $conn->query($sql);

    if ($result->num_rows > 0) 
    {
        echo "<table class='sqltable'>
                <tr class='sqltable'>
                    <th class='sqltable'>ID</th>
                    <th class='sqltable'>EMAIL</th>
                    <th class='sqltable'>NAME</th>
                    <th class='sqltable'>IS ADMIN</th>
                    <th class='sqltable'>PASSWORD</th>
                    <th class='sqltable'>CONTROLS</th>
                </tr>";

        // output data of each row
        while($row = $result->fetch_assoc()) 
        {
            echo "<tr class='sqltable'>                            
                    <td class='sqlcell'>".$row["ID"]."</td>
                    <td class='sqlcell'>".$row["EMAIL"]."</td>
                    <td class='sqlcell'>".$row["FIRST_NAME"]." ".$row["MID_NAME"]." ".$row["LAST_NAME"]."</td>
                    <td class='sqlcell'>".$row["IS_ADMIN"]."</td> 
                    <td class='sqlcell'>".$row["PASSWORD"]."</td>
                    <td class='sqlcell'>
                        <center>
                            <div style='border: 1px solid lightgray;' method='POST'>
                                <input type='hidden' name='ID' value='".$row['ID']." '/>
                                <input type='button' name='delete' value='DEL ".$row['ID']." '/>
                            </div>
                        </center>
                    </td>
                </tr>";
        } 
        echo "</table>";
    }

    else 
    {
        echo "DATABASE IS EMPTY!";
    }  

    $conn->close(); 

    if (isset($_POST['delete']))
    { //if a delete request received
        $id = $_POST['id']; //primary key of this row

        /////// Connectivity /////////
        $servername = "127.0.0.1";
        $username = "root";
        $password = ""; 
        $db = "myDB";    

        // Create connection
        $conn = new mysqli($servername, $username, $password, $db);

        //check connection
        if ($conn)
        {
            printf("Connect failed: %s\n", mysqli_connect_error());
            exit();
        }

        //compose sql statement
        $stmt = mysqli_prepare($conn, "DELETE FROM users WHERE ID=?");

        mysqli_stmt_bind_param($stmt,'i',$id); //now add the $id to the statement 'i' stands for integer

        mysqli_stmt_execute($stmt);

        mysqli_stmt_close($stmt);
        mysqli_close($conn); //connection closed
    }
?>

这就是我开始做的事情,我已经很确定自己走了错误的路线。

function delete()
            {
                $del = "DELETE FROM '".$table."' WHERE EMAIL='".$email."';";
                $conn->query($del);
            }

2 个答案:

答案 0 :(得分:0)

首先,php脚本是服务器端脚本,这意味着您的按钮不会触发删除功能,或者,它将向存在删除操作的服务器发送请求。

该怎么做?只需在要显示删除按钮的表格单元内呈现一个表单(即html元素),然后将方法定义为post(了解有关http请求方法的更多信息),然后可以包含id值(或该表的主键。

 <form method="post">
 <input type='submit' name='delete' />
 <input type='hidden' name="id" value="$row['id']" />
 </form>

因此,此表单告诉浏览器:每当用户单击“删除”按钮时,提交包含一个隐藏输入的此表单,其中包含要删除的元素的ID。

现在我们去服务器端,在文件的开头:

<?php 
if (isset($_POST['delete'])){ //if a delete request received
$id = $_POST['id']; //primary key of this row

//establish connection to mysql
$mysqli = new mysqli('localhost', 'my_user', 'my_password', 'world');

//check connection
if (mysqli_connect_errno()) {
    printf("Connect failed: %s\n", mysqli_connect_error());
    exit();
}

//compose sql statement
$stmt = $mysqli->prepare("DELETE FROM users WHERE ID=?");

$stmt->bind_param('i',$id); //now add the $id to the statement 'i' stands for integer

$stmt->execute();

$stmt->close();
$mysqli->close() //connection closed
}
?>

上面的代码以OOP编写,或者您可以以程序样式编写。.

<?php 
if (isset($_POST['delete'])){ //if a delete request received
$id = $_POST['id']; //primary key of this row

//establish connection to mysql
$mysqli = mysqli_connect('localhost', 'my_user', 'my_password', 'world');

//check connection
if (!$mysqli) {
    printf("Connect failed: %s\n", mysqli_connect_error());
    exit();
}

//compose sql statement
$stmt = mysqli_prepare($mysqli, "DELETE FROM users WHERE ID=?");

mysqli_stmt_bind_param($stmt,'i',$id); //now add the $id to the statement 'i' stands for integer

mysqli_stmt_execute($stmt);

mysqli_stmt_close($stmt);
mysqli_close($mysqli) //connection closed
}
?>
  1. more about binding parameters
  2. HTTP methods

答案 1 :(得分:0)

现在,当我实现问题中发布的代码时,为了使代码正常工作,我已经进行了一些更改,所有小问题,我都会在此处进行详细说明。

<?php
    if (isset($_POST['delete'])) //first: test if any delete request, delete and then render the table 
    { //if a delete request received
        $id = $_POST['id']; //primary key of this row, where 'id' index must be case-sensitively equal to the hidden input name 'id'

        /////// Connectivity /////////
        $servername = "localhost";
        $username = "root";
        $password = "root"; 
        $db = "user_delete";    

        // Create connection (procedural style)
        $conn = mysqli_connect($servername, $username, $password, $db);

        //check connection
        if (!$conn) //if NOT connected
        {
            printf("Connect failed: %s\n", mysqli_connect_error()); //print error
            exit(); //exit the program 'in this case you wouldn't see the table either'
        }

        //compose sql statement
        $stmt = mysqli_prepare($conn, "DELETE FROM users WHERE ID=?"); //notice that sql statements are NOT case sensitive

        mysqli_stmt_bind_param($stmt,'i',$id); //now add the $id to the statement 'i' stands for integer

        mysqli_stmt_execute($stmt);

        mysqli_stmt_close($stmt);
        mysqli_close($conn); //connection closed, row deleted
    }

    include "connection.php"; 

    $sql = "SELECT * FROM users;";
    $result = $conn->query($sql);

    if ($result->num_rows > 0) 
    {
        echo "<table class='sqltable'>
                <tr class='sqltable'>
                    <th class='sqltable'>ID</th>
                    <th class='sqltable'>EMAIL</th>
                    <th class='sqltable'>NAME</th>
                    <th class='sqltable'>IS ADMIN</th>
                    <th class='sqltable'>PASSWORD</th>
                    <th class='sqltable'>CONTROLS</th>
                </tr>";

        // output data of each row
        while($row = $result->fetch_assoc()) 
        {
            echo "<tr class='sqltable'>";
            echo   "<td class='sqlcell'>".$row["id"]."</td>";   //php is case-sensitive so you should use $row['ID'] according to your scheme
            echo   "<td class='sqlcell'>".$row["email"]."</td>";//php is case-sensitive so you should use $row['EMAIL'] according to your scheme
            echo   "<td class='sqlcell'>".$row["name"]."</td>";//for simplicity, I made one field, change it according to your scheme
            echo   "<td class='sqlcell'>".$row["is_Admin"]."</td>";//php is case-sensitive so you should use $row['IS_ADMIN'] according to your scheme
            echo   "<td class='sqlcell'>".$row["password"]."</td>";//same as above
            echo    "<td class='sqlcell'>
                        <center>
                            <div style='border: 1px solid lightgray;'>";
                    echo    "<form method='POST'>"; //must be added in a form with method=post
                    echo        "<input type='hidden' name='id' value='".$row['id']." '/>"; //differntiate between input name `id` and mysql field name you have `ID`, input field name is the index you will fetch in line 4: $_POST['id']
                    echo        "<input type='submit' name='delete' value='DEL ".$row['id']." '/>"; //type: submit, not button
                    echo    "</form>
                            </div>
                        </center>
                    </td>
                </tr>";
        } 
        echo "</table>";
    }

    else 
    {
        echo "DATABASE IS EMPTY!";
    }  
//all done
    $conn->close(); 
?>

更新:现在,这是相同的代码,都采用OOP样式,并且可以重复使用连接:

<?php
    include "connection.php"; 
    if (isset($_POST['delete'])) //first: test if any delete request, delete and then render the table 
    { //if a delete request received
        $id = $_POST['id']; //primary key of this row, where 'id' index must be case-sensitivly equal to the hidden input name 'id'

        //check connection
        if (mysqli_connect_errno()) //if connection error existed
        {
            printf("Connect failed: %s\n", mysqli_connect_error()); //print error
            exit(); //exit the program 'in this case you wouldn't see the table either'
        }

        //compose sql statement
        $stmt = $conn->prepare("DELETE FROM users WHERE ID=?"); //notice that sql statements are NOT case sensitive

        $stmt->bind_param('i',$id); //now add the $id to the statement 'i' stands for integer

        $stmt->execute();

        $stmt->close();
    }

    $sql = "SELECT * FROM users;";
    $result = $conn->query($sql);

    if ($result->num_rows > 0) 
    {
        echo "<table class='sqltable'>
                <tr class='sqltable'>
                    <th class='sqltable'>ID</th>
                    <th class='sqltable'>EMAIL</th>
                    <th class='sqltable'>NAME</th>
                    <th class='sqltable'>IS ADMIN</th>
                    <th class='sqltable'>PASSWORD</th>
                    <th class='sqltable'>CONTROLS</th>
                </tr>";

        // output data of each row
        while($row = $result->fetch_assoc()) 
        {
            echo "<tr class='sqltable'>";
            echo   "<td class='sqlcell'>".$row["id"]."</td>";   //php is case-sensitive so you should use $row['ID'] according to your scheme
            echo   "<td class='sqlcell'>".$row["email"]."</td>";//php is case-sensitive so you should use $row['EMAIL'] according to your scheme
            echo   "<td class='sqlcell'>".$row["name"]."</td>";//for simplicity, I made one field, change it according to your scheme
            echo   "<td class='sqlcell'>".$row["is_Admin"]."</td>";//php is case-sensitive so you should use $row['IS_ADMIN'] according to your scheme
            echo   "<td class='sqlcell'>".$row["password"]."</td>";//same as above
            echo    "<td class='sqlcell'>
                        <center>
                            <div style='border: 1px solid lightgray;'>";
                    echo    "<form method='POST'>"; //must be added in a form with method=post
                    echo        "<input type='hidden' name='id' value='".$row['id']." '/>"; //differntiate between input name `id` and mysql field name you have `ID`, input field name is the index you will fetch in line 4: $_POST['id']
                    echo        "<input type='submit' name='delete' value='DEL ".$row['id']." '/>"; //type: submit, not button
                    echo    "</form>
                            </div>
                        </center>
                    </td>
                </tr>";
        } 
        echo "</table>";
    }

    else 
    {
        echo "DATABASE IS EMPTY!";
    }  
//all done
    $conn->close(); 
?>

提示:在现实世界中,永远不要将密码存储为纯文本,不要搜索和阅读更多about hashing