-4

我保证,这将是今天的最后一个问题。但我收到错误“警告:mysql_fetch_assoc():提供的参数不是第 58 行 /home/a1014025/public_html/practice/cart/cart.php 中的有效 MySQL 结果资源”,代码如下:

<?php
include('connect.php');
session_start();
?>
<html>
<head>
    <title>Cart</title>
    <link rel='stylesheet' href='css/main.css' />
</head>
<body>
    <?php
    $page = 'index.php';

    if(isset($_GET['add'])){
        $add_id = $_GET['add'];
        $quantity = mysql_query("SELECT id, quantity FROM products WHERE id='$add_id'");
        while($quantity_row = mysql_fetch_assoc($quantity)){
            if($quantity_row['quantity'] !=@$_SESSION['cart_'.$add_id]){
                @$_SESSION['cart_'.$_GET['add']]+='1';
                header('Location: index.php');
            }
            else{
                header('Location: index.php?err=max');
            }
        }

    }

    if(isset($_GET['remove'])){
        $_SESSION['cart_'.(int)$_GET['remove']]--;
        header("Location: index.php");
    }

    if(isset($_GET['delete'])){
        $_SESSION['cart_'.(int)$_GET['delete']]='0';
        header('Location: index.php');
    }

    function products(){
        $get = mysql_query("SELECT id, name, description, price FROM products WHERE quantity > 0 ORDER BY id DESC");
        if(mysql_num_rows($get) == 0){
            echo "There are no products to display.";
        }
        else{
            while($get_row = mysql_fetch_assoc($get)){
                echo '<p>'.$get_row['name'].'<br />'.$get_row['description'].'<br />$'.$get_row['price'].' <a href="cart.php?add='.$get_row['id'].'">Add</a></p>';
            }
        }
    }

    function paypal_items(){
        $num = 0;
        foreach($_SESSION as $name => $value){
            if($value!=0){
                if(substr($name, 0, 5) == 'cart_'){
                    $id = substr($name, 5, strlen($name)-5);
                    $get = mysql_query("SELECT id, name, price, shipping, shipping2 FROM products WHERE id=".$id);
                    while($get_row = mysql_fetch_assoc($get)){
                        $num++;
                        echo '<input type="hidden" name="item_number_'.$num.'" value="'.$id.'">';
                        echo '<input type="hidden" name="item_name_'.$num.'" value="'.$get_row['name'].'">';
                        echo '<input type="hidden" name="amount_'.$num.'" value="'.$get_row['price'].'">';
                        echo '<input type="hidden" name="shipping_'.$num.'" value="'.$get_row['shipping'].'">';
                        echo '<input type="hidden" name="shipping2_'.$num.'" value="'.$get_row['shipping2'].'">';
                        echo '<input type="hidden" name="quantity_'.$num.'" value="'.$value.'">';

                    }
                }
            }
        }
    }

    function cart(){
        $total = 0;
        foreach($_SESSION as $name => $value){
            if($value>0){
                if(substr($name, 0, 5)=='cart_'){
                    $id = substr($name, 5, strlen($name)-5);
                    $get = mysql_query("SELECT id, name, price FROM products WHERE id='$id'");
                    while($get_row = mysql_fetch_assoc($get)){
                        $sub = $get_row['price']*$value;
                        echo $get_row['name'].' x '.$value.' @ $'.number_format($get_row['price'], 2).' = $'.$sub.' <a href="cart.php?add='.$id.'">[+]</a> <a href="cart.php?remove='.$id.'">[-]</a> <a href="cart.php?delete='.$id.'">[Delete]</a><br />';
                    }
                }
                $total += $sub; 
            }
        }
        if($total==0){
            echo "You cart is empty.";
        }
        else{
            echo "<p>Checkout with PayPal for your $".$total." total.</p>";
            ?>
            <form action="https://www.paypal.com/cgi-bin/webscr" method="post">
            <input type="hidden" name="cmd" value="_cart">
            <input type="hidden" name="upload" value="1">
            <input type="hidden" name="business" value="ddromano@comcast.net">
            <?php paypal_items(); ?>
            <input type="hidden" name="currency_code" value="USD">
            <input type="hidden" name="amount" value="<?php echo $total; ?>">
            <input type="image" src="http://www.paypal.com/en_US/i/btn/x-click-but03.gif" name="submit" alt="Make payments with PayPal - it's fast, free and secure!">
            </form>
            <?php

        }
    }

    ?>
</body>

4

2 回答 2

0

请停止抑制脚本中的错误。

@$_SESSION['cart_'.$_GET['add']]+='1';

启用错误报告可以让您更好地了解脚本中的问题所在。

该代码中的第 58 行指向:

57  $get = mysql_query("SELECT id, name, price, shipping, shipping2 FROM products WHERE id=".$id);
58  while($get_row = mysql_fetch_assoc($get)){
    ...

由于您在mysql_函数中使用资源,因此连接很可能超出范围。您必须将连接传递给函数或全球化连接。

function paypal_items($conn){

或者

function paypal_items(){
    global $conn;

我在您之前的问题中提到过,您似乎忽略了它;您的脚本容易受到 SQL 注入的攻击。我强烈敦促您了解这是什么,修复它并移至mysqli_or PDO

于 2013-02-16T01:25:50.503 回答
-1

看起来您在第 57 行的 SQL 中有错误 - 您的 id 值应该用引号引起来:

$get = mysql_query("SELECT id, name, price, shipping, shipping2 FROM products WHERE id='".$id."'");

您可以使用 php 自动报告此问题or

$get = mysql_query(...) or die(mysql_error());

顺便说一句,您确实应该在提交查询之前对其进行清理。每当您将变量传递到 SQL 语句中时,请使用它mysql_real_escape_string来防止 SQL 注入。

于 2013-02-16T01:14:37.933 回答