检查SQL PHP上的两列是否匹配

检查SQL PHP上的两列是否匹配,php,mysql,Php,Mysql,我有一个表单,用户必须输入他们的预订id和姓氏。如果这两个值在数据库中匹配,那么我需要从数据库返回相应的值 我有两个文件,一个是使用ajax的html文件,另一个是php文件。单击按钮时,没有返回任何内容,我没有看到任何特定错误,并且我确信输入的值是正确的 <script> var ajax = getHTTPObject(); function getHTTPObject() { var xmlhttp; if (window.XMLHttpRequest) {

我有一个表单,用户必须输入他们的预订id和姓氏。如果这两个值在数据库中匹配,那么我需要从数据库返回相应的值

我有两个文件,一个是使用ajax的html文件,另一个是php文件。单击按钮时,没有返回任何内容,我没有看到任何特定错误,并且我确信输入的值是正确的

<script>
var ajax = getHTTPObject();

function getHTTPObject()
{
    var xmlhttp;
    if (window.XMLHttpRequest) {
      // code for IE7+, Firefox, Chrome, Opera, Safari
      xmlhttp=new XMLHttpRequest();
    } else if (window.ActiveXObject) {
      // code for IE6, IE5
      xmlhttp=new ActiveXObject("Microsoft.XMLHTTP");
    } else {
      //alert("Your browser does not support XMLHTTP!");
    }
    return xmlhttp;
}

function updateCityState()
{
    if (ajax)
    {
        var reservation_id = document.getElementById("reservation_id").value;
          var guest_last_name = document.getElementById("guest_last_name").value;

        if(reservation_id)
        {

            var param = "?reservation_id=" + reservation_id + "&guest_last_name=" + guest_last_name;
var url = "test04.php";

            ajax.open("GET", url + param, true);
            ajax.onreadystatechange = handleAjax;
            ajax.send(null);

        }
    }
}
function handleAjax()                                                                                                                           
{
  if (ajax.readyState == 4)
   {
        var guest_full_name = document.getElementById('guest_full_name');

            var unit_number = document.getElementById('unit_number');

    var floor = document.getElementById('floor');

        var key_sa = document.getElementById('key_sa');




    if(!!ajax.responseText) {
      var result = JSON.parse(ajax.responseText);
      if(!!result){
         guest_full_name.innerHTML  = (!!result.guest_full_name) ? result.guest_full_name : '';

             unit_number.innerHTML = (!!result.unit_number) ? result.unit_number : '';


        floor.innerHTML = (!!result.floor) ? result.floor : '';


        key_sa.innerHTML = (!!result.key_sa) ? result.key_sa : '';
      } 
    }
   }
 }
</script>



<p id='employee_name'></p>
<p id='employee_age'></p>
<p id='safe_code'></p>

var ajax=getHTTPObject();
函数getHTTPObject()
{
var-xmlhttp;
if(window.XMLHttpRequest){
//IE7+、Firefox、Chrome、Opera、Safari的代码
xmlhttp=新的XMLHttpRequest();
}else if(window.ActiveXObject){
//IE6、IE5的代码
xmlhttp=新的ActiveXObject(“Microsoft.xmlhttp”);
}否则{
//警报(“您的浏览器不支持XMLHTTP!”);
}
返回xmlhttp;
}
函数updateCityState()
{
if(ajax)
{
var reservation\u id=document.getElementById(“reservation\u id”).value;
var guest\u last\u name=document.getElementById(“guest\u last\u name”).value;
如果(预订号)
{
var param=“?reservation_id=“+reservation_id+”&guest_last_name=“+guest_last_name;
var url=“test04.php”;
open(“GET”,url+param,true);
ajax.onreadystatechange=handleAjax;
send(null);
}
}
}
函数handleAjax()
{
if(ajax.readyState==4)
{
var guest_full_name=document.getElementById('guest_full_name');
var unit_number=document.getElementById('unit_number');
var floor=document.getElementById('floor');
var key_sa=document.getElementById('key_sa');
如果(!!ajax.responseText){
var result=JSON.parse(ajax.responseText);
如果(!!结果){
guest\u full\u name.innerHTML=(!!result.guest\u full\u name)?result.guest\u full\u name:“”;
unit_number.innerHTML=(!!result.unit_number)?result.unit_number:“”;
floor.innerHTML=(!!result.floor)?result.floor:“”;
key_sa.innerHTML=(!!result.key_sa)?result.key_sa:“”;
} 
}
}
}

我的test04.php

<?php

$conn = mysqli_connect("","","","");

$reservation_id = mysqli_real_escape_string($conn, $_GET['reservation_id']);
$guest_last_name = mysqli_real_escape_string($conn, $_GET['guest_last_name']);

$query = "SELECT reservation_id, guest_full_name, guest_last_name unit_number, floor, key_sa FROM reservations2 INNER JOIN guest ON (reservations2.reservation_id=guest.reservation_idg) INNER JOIN unit USING (unit_id) where reservation_id ='".$reservation_id."'AND guest_last_name ='".$guest_last_name."";


 $result = mysqli_query($conn, $query) or die(mysql_error());
$response = array();

if(mysqli_num_rows($result) > 0) {
    while($row = mysqli_fetch_assoc($result)) {



        $response['guest_full_name'] = ($row['guest_full_name'] != '') ? $row['guest_full_name'] : '';
         $response['unit_number'] = ($row['unit_number'] != '') ? $row['unit_number'] : '';

             $response['floor'] = ($row['floor'] != '') ? $row['floor'] : '';
        $response['key_sa'] = ($row['key_sa'] != '') ? $row['key_sa'] : '';



    }
}
echo  json_encode($response, true); 


?>

我没有看到任何具体的错误

  • 你在找什么
  • 您是否检查了PHP脚本的原始响应,或者只是查看了浏览器中呈现的内容
  • 您是否验证了错误日志记录是否正常工作,是否检查了日志
PHP的逻辑还不清楚——JSON数据和PHP数组不能处理多个记录,但可以处理多个记录。正确地实现REST会很好。这也应该应用身份验证,并使用CSRF进行安全保护——但我假设您出于说明目的而忽略了这些内容

编写代码不是为了处理故障或丢失的数据。考虑(注意所有与你所发表的内容的不同):


我唯一的建议是使用预先准备好的语句来减少对
mres
的需要,并提高安全性。@amina90如果您有新问题,请在花时间自己调试和研究之后,不要在这里问后续问题。@Rob,这个问题与上面的代码有关。我正在讨论使用上面提供的代码symcbean时遇到的错误。我也调试了我的代码,这就是我得到的错误。
<?php

$conn = mysqli_connect("","","","");
$response = array();

$reservation_id = mysqli_real_escape_string($conn, $_GET['reservation_id']);
$guest_last_name = mysqli_real_escape_string($conn, $_GET['guest_last_name']);

$query = "SELECT reservation_id, guest_full_name
  , guest_last_name unit_number, floor, key_sa 
  FROM reservations2 
  INNER JOIN guest 
  ON (reservations2.reservation_id=guest.reservation_idg) 
  INNER JOIN unit USING (unit_id) 
  WHERE reservation_id ='".$reservation_id."'
    AND guest_last_name ='".$guest_last_name."";
$result = mysqli_query($conn, $query);
if (!$result) {
      $response['status']=503
      $response['msg']="Error";
      trigger_error(mysql_error());
      finish($response);
      exit;
}

$response['status']=200;
$response['msg']='OK';
$response['guest_full_name'] = htmlentities($_GET['guest_last_name']);
$response['reservations']=array();

while($row = mysqli_fetch_assoc($result)) {
    $response['reservations'][]=array(
           'unit_number'=>$row['unit_number'],
           'floor'=>$row['floor'],
           'key_sa'=>$row['floor_sa']);
  }
}
finish($response);
exit;

function finish($response)
{
    header("HTTP/1.1 $response[status] $response[msg]");
    header("Content-type: application/json");
    echo  json_encode($response, true); 
}