Re: Empty Array?
| From: | M. Sokolewicz | Date: | Fri, 05 Oct 2007 12:47:25 +0000 |
| Subject: | Re: Empty Array? | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-262804@lists.php.net to get a copy of this message | ||
I'll just put my comments inline for you...
Dan Shirah wrote:
Okay, gotcha! I changed it to this and it works: <?php $request_id = $_GET['id']; $current_user = substr($_SERVER['AUTH_USER'], 13); You can't trust this info.
$lock_query = "SELECT id, locked_by_user FROM locked_payments WHERE id = '$request_id'"; WARNING :: SQL INJECTION :: WARNING
$lock_result = mssql_query($lock_query) or die(mssql_get_last_message()); $lock_row = mssql_fetch_array($lock_result); $lock_id = $lock_row['id']; $lock_user = $lock_row['locked_by_user']; You don't know if these 2 exist, so you'll get E_NOTICEs when you get 0 rows in your result
if (empty($lock_row)) { And now you check if it actually HAS data, why didn't you do this 2 lines earlier ?
$set_lock = "INSERT into locked_payments (
id,
locked_by_user)
VALUES
('$request_id',
'$current_user')";
WARNING :: SQL INJECTION :: WARNING
mssql_query($set_lock) or die ("Query failed: <br />".mssql_get_last_message()); } ?> Thanks! :) you're welcome.- Tul
On 10/5/07, Aleksandar Vojnovic <muadib@consoriana.com> wrote:I think the $lock_result is just a resource #id you haven't fetched any data yet. True? Aleksander Dan Shirah wrote:Ah, what a lovely case of the Friday morning brain farts! I have a query that selects some data from a table based on the currentIDselected. If the query does not return any results, I want it to continue toanotherquery that will insert a record into the table. Below is what I have...but it will not insert anything if the firstquerydoes not find a match. <?php $request_id = $_GET['id']; $current_user = substr($_SERVER['AUTH_USER'], 13); $lock_query = "SELECT id, locked_by_user FROM locked_payments WHERE id = '$request_id'"; $lock_result = mssql_query($lock_query) ordie(mssql_get_last_message());if (empty($lock_result)) { $set_lock = "INSERT into locked_payments ((empty($lock_result))id, locked_by_user) VALUES ('$request_id', '$current_user')";mssql_query($set_lock) or die ("Insert failed: <br />".mssql_get_last_message()); } ?> Any ideas on what I'm doing wrong? My guess is thatis probably not the correct way to check if an array is empty?