你好我正在创建登录历史记录。它可以成功登录,但问题是我无法将数据插入我的“登录历史”表...这是我的代码到目前为止。它可以成功登录,但不能将用户名插入我的登录历史记录表。
<?php
//Start session
session_start();
//Array to store validation errors
$errmsg_arr = array();
//Validation error flag
$errflag = false;
//Connect to mysql server
$link = mysql_connect('localhost','root',"");
if(!$link) {
die('Failed to connect to server: ' . mysql_error());
}
//Select database
$db = mysql_select_db(inventory, $link);
if(!$db) {
die("Unable to select database");
}
//Function to sanitize values received from the form. Prevents SQL injection
function clean($str) {
$str = @trim($str);
if(get_magic_quotes_gpc()) {
$str = stripslashes($str);
}
return mysql_real_escape_string($str);
}
//Sanitize the POST values
// Generate Guid
$login = clean($_POST['username']);
$password = clean($_POST['password']);
//Create query
$qry="SELECT * FROM admins WHERE username='$login' AND password='$password'";
$result=mysql_query($qry);
//Check whether the query was successful or not
if($result) {
if(mysql_num_rows($result) > 0) {
$sql="INSERT INTO log_history (emp_name)
VALUES ('$login')";
//Login Successful
session_regenerate_id();
$member = mysql_fetch_assoc($result);
$_SESSION['SESS_MEMBER_ID'] = $member['username'];
session_write_close();
header("location: auto.php?id=0");
exit();
}
else {
header("location: alert.php");
}
}
?>
答案 0 :(得分:0)
您似乎没有将所需的记录实际插入到历史记录表中:
$sql="INSERT INTO log_history (emp_name)
VALUES ('$username')";
// Should you run this insert query?
mysql_query($sql);
//Login Successful
session_regenerate_id();
$member = mysql_fetch_assoc($result);
$_SESSION['SESS_MEMBER_ID'] = $member['username'];
session_write_close();
我认为你错过了某处的执行声明。
此外,如果您刚刚开始,您真的应该考虑开始使用PDO和准备好的语句。虽然您正在进行一些基本的清洁,但您的代码仍然不是真正的防弹。 Take a read of this请考虑转到PDO并准备好陈述。
答案 1 :(得分:0)
要插入表log_history的代码在哪里?我没有看到它。 也许你需要打电话
$sql="INSERT INTO log_history (emp_name) VALUES ('$username')";
$result2=mysql_query($sql);