使用php将Excel数据导入数据库表

时间:2019-04-12 05:06:55

标签: php mysql excel

问题在我的Excel中存在369行。当我回显/打印该数据时,它显示正确,但是当我在插入18至30条记录的DB表中插入相同数据时。

if (isset($_POST['Submit'])) {
    $file = $_FILES['csv_file']['tmp_name'];
    $handle = fopen($file, "r");
    if ($file == NULL) {
    error(_('Please select a file to import'));
    redirect(page_link_to('excel_data_upload'));
    }else {
        $conn = connect();
        while(($filesop = fgetcsv($handle, 1000, ",")) !== false)
        {
            $num3 = $filesop[3];
            $num8 = $filesop[8];
            $num9 = $filesop[9];
            $num20 = $filesop[20];
            if($num3!='ExpiryDate' &&$num8!='VCNO' &&$num20!='TotalB2CAmount' && $num9 !='STBNO'){

                $insertAgent =  mysqli_query($conn, "INSERT INTO `upload_billing_data` 
                (`vc_number`,`stb_number`,`operator_id`,`expiry_date`,`monthly_bill_amount`) 
                VALUES ('$num8','$num9',140,'$num3','$num20')");

                if($insertAgent)
                {
                    echo 'succss';
                }else{
                    echo 'error';
                }

            }  
        }
        close($conn);

    }
}

我正在从Excel数据中获取。我要插入所有记录

2 个答案:

答案 0 :(得分:0)

按如下所示更改代码,您可能会使用一个查询将所有数据保存到数据库:

$query_insert = array();

while(($filesop = fgetcsv($handle, 1000, ",")) !== false) {
   $num3 = filterString($filesop[3]);
   $num8 = filterString($filesop[8]);
   $num9 = filterString($filesop[9]);
   $num20 = filterString($filesop[20]);

   if ($num3!='ExpiryDate' &&$num8!='VCNO' &&$num20!='TotalB2CAmount' && $num9 !='STBNO') {
      $query_insert[] = "('{$num8}', '{$num9}', 140, '{$num3}', '{$num20}')";
   }  
}

// If no row matched your if, then there will be no row to add to the database
if (count($query_insert)>0) {
   $conn = connect();

   $query_insert_string = implode(', ', $query_insert);

   $query = "INSERT INTO `upload_billing_data` (`vc_number`, `stb_number`, `operator_id`, `expiry_date`, `monthly_bill_amount`) VALUES {$query_insert_string};";
   $insertAgent = mysqli_query($query);

   // The rest of you code 
   ...

   close($conn);
}



// This function makes sure that you string doesn't contain characters that might damage the query
function filterString($string) {
   $string = str_replace(array("\'", '"'), array('', ''), $string);
   $string = filter_var($string, FILTER_SANITIZE_STRING);
   return $string;
}

答案 1 :(得分:0)

请检查此修改后的代码

if (isset($_POST['Submit'])) {
    $file = $_FILES['csv_file']['tmp_name'];
    $handle = fopen($file, "r");
    if ($file == NULL) {
    error(_('Please select a file to import'));
    redirect(page_link_to('excel_data_upload'));
    }else {
        $conn = connect();
        while(($filesop = fgetcsv($handle, 1000, ",")) !== false)
        {
            $num3 = $filesop[3];
            $num8 = $filesop[8];
            $num9 = $filesop[9];
            $num20 = $filesop[20];
            if($num3!='ExpiryDate' &&$num8!='VCNO' &&$num20!='TotalB2CAmount' && $num9 !='STBNO'){

                $insertAgent =  mysqli_query($conn, "INSERT INTO `upload_billing_data` 
                (`vc_number`,`stb_number`,`operator_id`,`expiry_date`,`monthly_bill_amount`) 
                VALUES ('".mysqli_real_escape_string($num8)."','".mysqli_real_escape_string($num9)."',140,'".mysqli_real_escape_string($num3)."','".mysqli_real_escape_string($num20)."')");

                if($insertAgent)
                {
                    echo 'succss';
                }else{
                    echo 'error';
                }

            }  
        }
        close($conn);

    }
}

通过使用mysqli_real_escape_string(),您可以避免sqlinjection问题,并且可以处理可能引起问题的引号问题。

在您所在的echo "error"所在的else块中。您可以使用mysqli_error($conn);来获取执行插入操作时发生的错误的确切信息