Re: Forms

From: Date: Tue, 06 May 2003 12:12:44 +0000
Subject: Re: Forms
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-146504@lists.php.net to get a copy of this message
C.R. wrote:
I'm trying to use an image as a submit button in a form and getting some stupid error I just can't figure out. I have four seperate forms on my site and 3 of them work and one doesn't. I have copied and pasted the input line so they are the same in all four, so I am at a loss. This is the line.... <INPUT TYPE="image" src="images/arrow-r.gif" width="56" height="24" border="0">
You are specifying an image map, not just an image button. That means that the x,y coordinates of the mouse in "images/arrow-r.gif" when it is clicked are being sent as part of the form. Normally, you would specify a name for the image map e.g. <INPUT TYPE="image" NAME="myname", in which case the coordinates would be in $mynamex and $mynamey. As you have no name, the coordinates are just in $x and $y. Your script is trying to store these variables in your mysql table which is complaining that it doesn't have a field called x or y. And the solution is... Don't try be so lazy/cute! Specify the mysql fields explicitly i.e. replace
$query = "UPDATE $userinfotable SET "; foreach($_POST as $field=>$value) { $upfields[] = "$field='$value'"; } $sqlfields = implode($upfields,","); $query .= $sqlfields. " WHERE userid = '$userid'";
with $query = "UPDATE $userinfotable set myfield1 = '$myfield1' ,myfield2='$myfield2' ... WHERE userid = '$userid'"; etc. I guess you wanted to only have to change your form and table when you add extra fields and leave the code to automatically generate the query from the fields specified. The problem is that you have created a restriction on your form i.e. it must only ever submit fields in the database, so you can't use TYPE="image" or extra hidden variables or indeed anything except fields that are definitely in your table. This is a bad idea in principle since you are creating a potentially fatal code/representation dependency. It really doesn't take much extra work to actually TYPE the names of the fields, and since you already have to change the table and the form for new fields it doesn't add much maintenance overhead. Or perhaps you were trying to share the php code between several forms/tables. Sounds pretty iffy to me, (how will you ever do field-specific validation?). But if you really, really want this kind of general technique then you should use the mysql table definition to cross-check the list of fields to update rather than just the list of POSTed variables. i.e. something like this $fieldpointer = mysql_list_fields($database,$userinfotable); while ($fieldname = mysql_fieldname($fieldpointer)) { $dbfields[] = $fieldname; } and then $query = "UPDATE $userinfotable SET "; foreach($_POST as $field=>$value) {
    if (in_array($field,$dbfields)
    {
    $upfields[] = "$field='$value'";
    }
} $sqlfields = implode($upfields,","); $query .= $sqlfields. " WHERE userid = '$userid'"; This would work, although it will be slightly slower because of the overhead of picking up the mysql field list. It removes the immediate problem of image maps, but it still leaves representation/code dependencies. For example, you can't use your code to process "GET" update requests or command line (environment variable) requests automatically for you, since you are dependent on data coming via the "POST". If you try to get round that by you skipping the foreach ($_POST... and just using the mysql field list, you will probably update too much since you will be updating every field including userid and any timestamps or fields not in the form. So my advice is to keep it simple, and just name the fields in the query. In that case, your php doesn't have to know or care where the data came from, POST, GET, Environment, whatever. It will also be much easier for someone else to understand and maintain your code; more flexible, (you can easily add field specific processing e.g. myfield = '".strtoupper($myfield1."'), and less likely to break with "stupid errors you can't work out". Good luck, George
but .....this will work. <INPUT TYPE="submit" value="Submit"> This is being sent to a PHP script which will then write the form info to a MySQL database - the error I am getting is this: Unknown column 'x' in 'field list'. So where is it getting the column 'x' from? This is the top of the form on all four forms (other than the ACTION = and FORM NAME). <FORM NAME="Update Profile" Target"contentFrame" ACTION="editcheck.php" METHOD="POST" CLASS="formstyle"> The only thing I can think of that is causing the problem is the following, but I have no idea why. Any help is appreciated. $query = "UPDATE $userinfotable SET "; foreach($_POST as $field=>$value) { $upfields[] = "$field='$value'"; } $sqlfields = implode($upfields,","); $query .= $sqlfields. " WHERE userid = '$userid'";


« previous php.general (#146504) next »