我有点迷路,试图解决这个错误,请裸露在我身边。当我单击“提交”按钮时,页面似乎会刷新,并且没有显示假定读取“已完成”或“未”的消息。我添加了一些Ajax函数来动态地为MySQL数据库中的信息填充一些下拉列表。点击事件只是刷新页面?
问题:为什么我的网页没有提交,它只是'提神'?(后添加的Ajax功能和填充从PHP文件下拉列表)用于填充材料下拉
<SCRIPT type="text/javascript">
function populatematerial(str)
{
if (window.XMLHttpRequest)
{
// IE7+, Firefox, Chrome, Opera, Safari
xmlhttp=new XMLHttpRequest();
}
else
{
// IE6, IE5
xmlhttp=new ActiveXObject("Microsoft.XMLHTTP");
}
xmlhttp.onreadystatechange=function()
{
if (xmlhttp.readyState==4 && xmlhttp.status==200) {
document.getElementById("txtHint").innerHTML=xmlhttp.responseText;
}
}
xmlhttp.open("GET","getmaterial.php?q="+str,true);
xmlhttp.send();
}
<form name='form1' method="POST" action="<?php echo $_SERVER['PHP_SELF']; ?>">
<table border="0" width="100%" id="table1">
<tr>
<td width="144">DB Username</td>
<td><input type="text" name="dbusername" size="32"></td>
</tr>
<tr>
<td width="144">DB Password</td>
<td><input type="password" name="dbpassword" size="32"></td>
</tr>
<tr>
<td width="144">Tank Type</td>
<td><select name="tanktype" id="tools" onChange="populatematerial(this.value)">
<option></option>
<option value="Metal">Metal</option>
<option value="Rinse">Rinse</option>
</select>
</td>
</tr>
<tr id="material_show" style="display:none;">
<td width='144'>Material</td>
<td>
<select size='1' name='material' id="txtHint">
</select>
</td>
</tr>
</table>
<p><input type="submit" value="Submit" name="result" ></p>
<?php
if (isset($_POST['result']))
{
session_start();
// check user id and password
if (!authorized($dbuser1,'#####')) {
echo "<h2>You are not authorized. Sorry.</h2>";
// exit to different page
}
// open database connection
// upload some data via $submitquery
mysql_query($submitquery) or die('UNABLE TO SUBMIT DATA');
echo "<b>Submit Successful</b><p>";
// close database connection
?>
PHP文件:
<?php
$q=$_GET["q"];
// open database connection
$query = "select * from r2rtool.platingmaterialtype where type = '".$q."'";
$result = mysql_query($query);
$option = "";
while($row = mysql_fetch_array($result))
{
$option.="<option value=\"{$row['Material']}\">{$row['Material']}</option>";
}
echo "<option value='0'></option>";
echo $option;
// close database connection
?>
在附注中,$ _SERVER ['PHP_SELF']可能会为XSS攻击留下开口。看看这篇文章:http://www.mc2design.com/blog/php_self-safe-alternatives – jwatts1980
@ jwatts1980这是在一个安全的内部网络没有公共访问。 – TheRealDK
真的只是刷新页面吗?快速检查方法是在提交后实际刷新页面,以查看浏览器是否警告您重新发布数据。或者点击提交,启动提琴手或IE的网络分析器并观察网络流量。 – gilly3