Jump to content

Simple update database help


Recommended Posts

Ok so im trying to make a form where the user can update their status and when i do update it it just clears the information already in the table but doesnt replace it with the new information... Can anyone spot why?


form :


<table class="acc_status_bg" cellpadding="0" cellspacing="0" style="width: 506; height: 180">


				// Retrieve data from database 
				$sql="SELECT * FROM biggartfp9_user_infot WHERE Username='$username'";

				// Start looping rows in mysql database.
				<form method="post" action="update_status.php?username=<?php echo "$username" ?>">
							<td class="acc_status_h">What are you doing right now? 
							<td class="acc_status_200">200</td>
							<td colspan="2" class="acc_status_input">

								<textarea class="acc_status_textarea"name="TextArea1" rows="2" style="width: 478px"></textarea></td>
							<td colspan="2" class="acc_status_submit">
								<input class="acc_status_update"name="Update" type="submit" value="Update"/>
							<td colspan="2" class="acc_status_post"><?php echo $rows['Status']; ?></td>
							<td colspan="2" class="acc_status_posted">Posted on : <?php echo $rows['Status_date']; ?></td>
				// close while loop 
				// close connection 



php :



$sql="UPDATE biggartfp9_user_infot SET Status='$Status' WHERE Username='$name'";

// if successfully updated.

else {
echo "ERROR";
// close connection

Link to comment
Share on other sites

i don't see an input field for Status.  you need to create a field:


<input type="whatever" name="[b]Status[/b]" />


as well, change this line:






$result=mysql_query($sql) or trigger_error (mysql_error());


AND use mysql_real_escape_string();


$name=mysql_real_escape_string ($_GET['username']);
$Status=mysql_real_escape_string ($_POST['Status']);

Link to comment
Share on other sites

You don't have anywhere in your html form a control with the name status as far as I can see... The PHP POST variable that is supposed to return status of course will wind up blank in that situation. I'm guessing it is the "TextArea1" that you are trying to use to update with. In this case you must name this Status

Link to comment
Share on other sites

Link: mysql_real_escape_string()


Escapes special characters in the unescaped_string ' date=' taking into account the current character set of the connection so that it is safe to place it in a mysql_query() ... mysql_real_escape_string() calls MySQL's library function mysql_real_escape_string, which prepends backslashes to the following characters: \x00, \n, \r, \, ', " and \x1a.[/quote']


basically, it helps make the inputted variables safe® against SQL injections within your database queries.


check out Example#2 in the manual for more on why this is useful.

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.