我得到奇怪的输出

时间:2019-04-19 15:04:16

标签: javascript php mysql

因此,我试图在用户注册或登录后从我的mysql数据库中检索数据。问题是它以某种方式检索了字母“ u”,这很奇怪,因为没有位置包含字母“ u”。

这是我到目前为止得到的结果 https://imgur.com/t3XBrPN

index.php(用户注册或登录的地方)

<?php include('server.php') ?>


<!DOCTYPE html>
<html lang="en">
<head>
  <meta charset="UTF-8">
  <meta name="viewport" content="width=device-width, initial-scale=1">
  <meta http-equiv="X-UA-Compatible" content="ie=edge">

  <title>PwettyKittyPincesa</title>

  <link href="./style.css" type="text/css" rel="stylesheet" />

  <script>
      function start(){
        closeForm();
        closeRegForm();
      }

      function openForm() {
        document.getElementById("myForm").style.display = "block";
        closeRegForm();
      }

      function closeForm() {
        document.getElementById("myForm").style.display = "none";
      }

      function openRegForm() {
        document.getElementById("myRegForm").style.display = "block";
        closeForm();
      }

      function closeRegForm() {
        document.getElementById("myRegForm").style.display = "none";
      }
      </script>

</head>
<body onload="start()">
  <nav>
      <button class="button" type="submit" onclick="openForm()">Влез</button>
      <button class="buttonReg" type="submit" onclick="openRegForm()">Регистрирай се</button>
      <img src="Logo4.png" class="Logo" alt="Logo">
  </nav>

  <div class="form-popupRegister" id="myRegForm">
    <form method="post" action="server.php" class="form-containerReg">

        <h1>Регистрирация</h1>

        <label for="username"><b>Име</b></label>
        <input type="text" name="username" placeholder="Въведете името на лейдито" value="<?php echo $username; ?>">


        <label for="email"><b>Е-майл</b></label>
        <input type="email" name="email" placeholder="Въведете e-mail" value="<?php echo $email; ?>">


        <label for="password_1"><b>Парола</b></label>
        <input type="password" placeholder="Въведете парола" name="password_1">


        <label for="password_2"><b>Повторете Парола</b></label>
        <input type="password" placeholder="Въведете парола повторно" name="password_2">


        <button type="submit" class="btnReg" name="reg_user">Register</button>
        <button type="button" class="btn-cancelReg" onclick="closeRegForm()">Close</button>
    </form>
</div>

  <div class="form-popup" id="myForm">
    <form method="post" action="server.php" class="form-container">

        <h1>Влизане</h1>

            <label for="username"><b>Име</b></label>
            <input type="text" name="username" value="<?php echo $username; ?>">

            <label for="password"><b>Парола</b></label>
            <input type="password" name="password">

            <button type="submit" class="btn" name="login_user">Login</button>
            <button type="button" class="btn-cancel" onclick="closeForm()">Close</button>
    </form>
  </div>
</body>
</html>

index2.php(应在其中输出数据)

<?php include('server.php') ?>

<!DOCTYPE html>
<html lang="en">
<head>
  <meta charset="UTF-8">
  <meta name="viewport" content="width=device-width, initial-scale=1">
  <meta http-equiv="X-UA-Compatible" content="ie=edge">

  <title>PwettyKittyPincesa</title>

  <link href="./style.css" type="text/css" rel="stylesheet" />

  <script>
    function getUserStats(){
        <?php
            $queryThree = "SELECT * FROM `register` WHERE ID='$idQuery' ";
            $userStats = mysqli_query($db,$queryThree);
            $userStatsTwo = mysqli_fetch_assoc($userStats);
        ?>
    }
  </script>
</head>
<body onload="getUserStats()">
    <div class="navWrapper">
        <div class="statistics">
            <div class="profilePicture" name="profilePicture">
                <label class="profilePictureLabel" for="profilePicture"><b><?php echo userStatsTwo['username']; ?></b></label>
            </div>

            <div class="money" name="money">
                <label class="rubyLabel" for="ruby"><b><?php echo userStatsTwo['money']; ?></b></label>
            </div>

            <div class="diamond" name="diamond">
                <label class="diamondLabel" for="diamond"><b><?php echo userStatsTwo['diamonds']; ?></b></label>
            </div>

            <div class="ruby" name="ruby">
                <label class="rubyLabel" for="ruby"><b><?php echo userStatsTwo['ruby']; ?></b></label>
            </div>

            <div class="level" name="level">
                <label class="levelLabel" for="level"><b>Level:<?php echo userStatsTwo['level']; ?></b></label>
            </div>
        </div>
    </div>
</body>
</html>

server.php(正在处理数据的地方)

<?php
session_start();

// initializing variables
$username = "";
$email    = "";
$idQuery = "";
$errors = array(); 


// connect to the database
$db = mysqli_connect('localhost', 'id9159890_uregisterdb', 'censored', 'id9159890_registerdb');

// REGISTER USER
if (isset($_POST['reg_user'])) {
  // receive all input values from the form
  $username = mysqli_real_escape_string($db, $_POST['username']);
  $email = mysqli_real_escape_string($db, $_POST['email']);
  $password_1 = mysqli_real_escape_string($db, $_POST['password_1']);
  $password_2 = mysqli_real_escape_string($db, $_POST['password_2']);

  // form validation: ensure that the form is correctly filled ...
  // by adding (array_push()) corresponding error unto $errors array
  if (empty($username)) { array_push($errors, "Username is required"); }
  if (empty($email)) { array_push($errors, "Email is required"); }
  if (empty($password_1)) { array_push($errors, "Password is required"); }
  if ($password_1 != $password_2) {
    array_push($errors, "The two passwords do not match");
  }

  // first check the database to make sure 
  // a user does not already exist with the same username and/or email
  $user_check_query = "SELECT * FROM `register` WHERE username='$username' OR email='$email' LIMIT 1";
  $result = mysqli_query($db, $user_check_query);
  $user = mysqli_fetch_assoc($result);

  if ($user) { // if user exists
    if ($user['username'] === $username) {
      array_push($errors, "Username already exists");
    }

    if ($user['email'] === $email) {
      array_push($errors, "email already exists");
    }
  }

  // Finally, register user if there are no errors in the form
  if (count($errors) == 0) {
    $password = md5($password_1);//encrypt the password before saving in the database

    $query = "INSERT INTO `register` (username, password, email, money, ruby, diamonds, levelpoints, level)
    VALUES ('$username', '$password', '$email', '0', '0', '0', '0', '0')";
    mysqli_query($db, $query);

    $idQuery = "SELECT ID FROM `register` WHERE username='$username'";
    mysqli_query($db, $idQuery);
    $_SESSION['username'] = $username;
    $_SESSION['userid'] = $idQuery;
    $_SESSION['success'] = "You are now logged in";
    header('location: index2.php');
  }
}


// LOGIN USER
if (isset($_POST['login_user'])) {
  $username = mysqli_real_escape_string($db, $_POST['username']);
  $password = mysqli_real_escape_string($db, $_POST['password']);

  if (empty($username)) {
    array_push($errors, "Username is required");
  }
  if (empty($password)) {
    array_push($errors, "Password is required");
  }

  if (count($errors) == 0) {
    $password = md5($password);
    $query = "SELECT * FROM `register` WHERE username='$username'";
    $results = mysqli_query($db, $query);
    if (mysqli_num_rows($results) == 1) {
      $_SESSION['username'] = $username;
      $_SESSION['success'] = "You are now logged in";
      header('location: index2.php');
    }else {
        array_push($errors, "Wrong username/password combination");
    }
  }
}

  ?>

我应该得到的结果是(从上到下,从左到右) 用户名,级别,资金,钻石,红宝石及其值应分别为用户名,0、0、0、0。

我已经尝试了所有内容,没有任何变化,我重新构造了两次代码,但它仍然只输出那些内容,而没有其他内容。

1 个答案:

答案 0 :(得分:0)

您的代码中有一个问题:

$idQuery = "SELECT ID FROM `register` WHERE username='$username'";
mysqli_query($db, $idQuery);
$_SESSION['username'] = $username;
$_SESSION['userid'] = $idQuery;

正如我在评论中提到的,请检查您在echo "SELECT * FROM register WHERE ID='$idQuery' ";中得到了什么,您肯定会得到这种结果:

SELECT * FROM register` WHERE ID= 'SELECT ID FROM `register` WHERE username='somename''

对于子查询,请从以下位置删除变量周围的引号:

"SELECT * FROM register` WHERE ID='$idQuery' ";

应为:

"SELECT * FROM register` WHERE ID = $idQuery";

请注意,这是成功的案例,当您在https://imgur.com/P64hqvI处显示结果时,查询工作正常。

如果$idQuery还需要对$idQuery == ''使用某种保护,那么您也将无法获得任何结果。

如@ patrick-q所述,请使用会话存储usernameID,而不是保存完整的查询。

第二,您的代码可以进行SQL注入,以防止使用PDO。

一些有用的链接:

Are PDO prepared statements sufficient to prevent SQL injection?

How can I prevent SQL injection in PHP?