dongyinzheng6572 2015-11-04 01:39
浏览 21
已采纳

从$ _SESSION PHP获取多个表中的数据

currently I want to get two different data from two tables when users login to the system. The entitle table is "user","user_staff" and "user_group". But when the user enter its username and password and submit it prompt "Fatal error: Call to a member function fetch_array() on a non-object in C:\xampp\htdocs\auditsystem\index.php on line 26"

Below are the code:

if($username!= "" && $password != "")
{
//INNER JOIN user_group_module_role ON user.user_group_module_role_id = user_group_module_role.id
    $result =  $db->query("SELECT * FROM user 
                            INNER JOIN user_staff ON user.user_staff_id = user_staff.id
                            WHERE username = '$username' AND password = '$password'"); 



    if($result->num_rows == 1)
    {
        $validate = $result->fetch_assoc();

        $query1 = "SELECT * FROM usergroup WHERE id = $validate[user_group_id]";
        $result1 = $db->query($query1);
        $row1 = $result1->fetch_array();
        //change here for the authority 
        $_SESSION['user_staff'] = $validate['displayname'];
        $_SESSION['usergroup'] = $row1['user_group_type'];
        echo "<script language='javascript'>window.location='panel.php'</script>"; 
    }
    else
    {
        echo "<script>alert('Sorry, wrong username and password please check.')</script>";
    }
}
  • 写回答

1条回答 默认 最新

  • dongxing2263 2015-11-04 01:50
    关注

    Your query is malformed and is failing. This makes $result1 null/false. Your queries are also vulnerable to SQL Injection!

    if($username!= "" && $password != ""){
    //INNER JOIN user_group_module_role ON user.user_group_module_role_id = user_group_module_role.id
        $result =  $db->query("SELECT * FROM user INNER JOIN user_staff ON user.user_staff_id = user_staff.id WHERE username = '$username' AND password = '$password'"); 
        if($result->num_rows == 1){
            $validate = $result->fetch_assoc();
            $query1 = "SELECT * FROM usergroup WHERE id = {$validate['user_group_id']}";
            if($result1 = $db->query($query1)){
                $row1 = $result1->fetch_array();
                //change here for the authority 
                $_SESSION['user_staff'] = $validate['displayname'];
                $_SESSION['usergroup'] = $row1['user_group_type'];
                echo "<script language='javascript'>window.location='panel.php'</script>"; 
            } else {
                echo "<script language='javascript'>alert('SQL Error.');</script>";
            }
        } else {
            echo "<script>alert('Sorry, wrong username and password please check.')</script>";
        }
    }
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 装 pytorch 的时候出了好多问题,遇到这种情况怎么处理?
  • ¥20 IOS游览器某宝手机网页版自动立即购买JavaScript脚本
  • ¥15 手机接入宽带网线,如何释放宽带全部速度
  • ¥30 关于#r语言#的问题:如何对R语言中mfgarch包中构建的garch-midas模型进行样本内长期波动率预测和样本外长期波动率预测
  • ¥15 ETLCloud 处理json多层级问题
  • ¥15 matlab中使用gurobi时报错
  • ¥15 这个主板怎么能扩出一两个sata口
  • ¥15 不是,这到底错哪儿了😭
  • ¥15 2020长安杯与连接网探
  • ¥15 关于#matlab#的问题:在模糊控制器中选出线路信息,在simulink中根据线路信息生成速度时间目标曲线(初速度为20m/s,15秒后减为0的速度时间图像)我想问线路信息是什么