php help PLz

Joined
Oct 14, 2009
Messages
236
Reaction score
18
Can Someone Look at my code and tell me what is wrong
My insturctor says that we are creating a bog report system
When you click Create bug > it takes you to a form to create a bug then when you click submit it suppose to create a table in a database that is already created and fields here is my code for that
PHP:
<?php $required = array('bdesc', 'ldesc', 'actaken');
$error = FALSE;
foreach($required as $field){
	if (empty($_POST[$field])){
		$error = TRUE;
	}
}
if ($error){
	echo "All Fields are required.";
	echo "<p><a href ='NewBug.php'>Click here to go back</a></p>";
}else {
	include ('config.php');
if ($dbconnect !== FALSE) {
	$Tablename = "4530ceevulukwu";
	$SQLstring = "SHOW TABLES LIKE '$Tablename'";
	$QueryResult = Mysql_query($SQLstring,$dbconnect);
	if (mysql_num_rows($QueryResult) == 0){
		$SQLstring = "CREATE TABLE 4530ceevulukwu (ticketID SMALLINT NOT NULL AUTO_INCREMENT PRIMARY KEY, bdesc CHAR(80), ldesc CHAR(100), actaken CHAR(100))";
		$QueryResult = Mysql_query($SQLstring, $dbconnect);
		if ($QueryResult === FALSE)
			echo "<p> Unable to create the reporting system table.</p>"."<p>Error Code" .mysql_errno($dbconnect). ":" .mysql_error($dbconnect) . "</p>";
			else 
			echo "<p> sucessfully created the the reporting table.</p>";
	}	
	
	 $SQLstring = "INSERT INTO $Tablename (bdesc, ldesc, actaken) VALUES ('$bdesc', '$ldesc', '$actaken')";
	 $QueryResult = Mysql_query($SQLstring, $dbconnect);
	 if ($QueryResult === FALSE) {
	 	echo "<p> unable to insert the values into the report table.</p>"."<p> Error code" .mysql_errno($dbconnect).":" . mysql_error($dbconnect) . "</p>";
		
	 }else {
			$ticketID = mysql_insert_id($dbconnect);
			echo "<h1>Entry Saved</h1>\n";
			echo "<p>Robo System assigned your ID as $ticketID.</p>\n";
			echo "<p><a href='Project4.php'>Back to Bug Main Page</a></p>";
		
	 
	 }
	  mysql_close($dbconnect);

 }
 
}



?>


Now after that there should be a link that you can click on that views all the bugs you have created in the sql on a table
here is my code
PHP:
<?php
include ('config.php');
if ($dbconnect !== FALSE){
$Tablename = "4530ceevulukwu";
$SQLstring = "SELECT * FROM $Tablename";
$QueryResult = mysql_query($SQLstring);
if ($QueryResult === FALSE)
echo"<p> unable to execute the query.</p>". "<p>Error code". mysql_errno($dbconnect). ":". mysql_error($dbconnect). "</p>";
echo "<table width ='100%' border='1'>\n";
echo "<tr><th>ID</th><th>Brief Description</th><th>Long Description</th><th>Resolution/Action Taken</th></tr>\n";
while (($Row = mysql_fetch_array($QueryResult))) {
	echo "<tr><td>".$Row['ticketID']."</td><td>". $Row['bdesc']."</td><td>".$Row['ldesc']."</td><td>".$Row['actaken']. "</td></tr>\n";
}
echo "</table>\n";
echo "<p><a href='Project4.php'>Back to Bug Main Page</a></p>";
mysql_close($dbconnect);
}
?>

BTW forgot to mention that the cofig file is just a connector to the database
MY question is for some reason when i go to view all the bugs nothing shows up just numbers

i really dont know the error i did here
 
why do you create a new table for every bug?

Where do you see that? From what I see, he creates the table if it doesn't exist, but other than that, he's using the same table.

Albeit, the name of the table is rather strange... and code doesn't seem very safe. For example, if the script fails to create the table, the execution of the script still continues and will try to insert a row into the table. You should exit the script if it failed at creating the table.

Which brings another point, checking to see if the table was created or not is not very efficient every time this script is called. If you look around at other projects, you'll see that tables are created at the very beginning of an application installation. You should leave that logic out of your script, and create the SQL tables in the very beginning. Good way to do this is to have a install.php file inside your app directory, if a bootstrap script picks it up, assume that installation needs to be done, where you will do first-time initialization and other things. Lazy initialization like the one you demonstrate in your code is very bad and hard to maintain.

Imagine having hundreds of tables, and you create them across a bunch scripts. What if you make a change to a table? You will have to find all scripts that create the table, and modify it so it doesn't break the application. I suggest using things like phpmyadmin to design the table, then create an SQL dump, and in the installation script, you just execute that SQL dump.
 
Where do you see that? From what I see, he creates the table if it doesn't exist, but other than that, he's using the same table.

Albeit, the name of the table is rather strange... and code doesn't seem very safe. For example, if the script fails to create the table, the execution of the script still continues and will try to insert a row into the table. You should exit the script if it failed at creating the table.

Which brings another point, checking to see if the table was created or not is not very efficient every time this script is called. If you look around at other projects, you'll see that tables are created at the very beginning of an application installation. You should leave that logic out of your script, and create the SQL tables in the very beginning. Good way to do this is to have a install.php file inside your app directory, if a bootstrap script picks it up, assume that installation needs to be done, where you will do first-time initialization and other things. Lazy initialization like the one you demonstrate in your code is very bad and hard to maintain.

Imagine having hundreds of tables, and you create them across a bunch scripts. What if you make a change to a table? You will have to find all scripts that create the table, and modify it so it doesn't break the application. I suggest using things like phpmyadmin to design the table, then create an SQL dump, and in the installation script, you just execute that SQL dump.

My bad, just woke up when I wrote that >.>
Oh well, What you just wrote is totally right, but don't forget he just started though qq
 
You could also change the foreach to this

Code:
foreach($required as $field){
    if (empty($_POST[$field])){
        $error = TRUE;
    }
    else{
        $$field = mysql_real_escape_string($_POST[$fiedl]);
    }
}

It just simply turns the POSTS into variables like you are using them :P Any post you add to the $required array is set to a variable.
So for example $_POST['bdesc'] becomes $bdesc.

On top of that it escapes the strings to be safer from SQL Injections, although I recommend using PDO for that.
http://stackoverflow.com/questions/3716373/real-escape-string-and-pdo

I used to use that when I was programming procedural a lot.

In case you don't understand the double dollar sign take a look at this:
http://www.php.net/manual/en/language.variables.variable.php
 
Last edited:
You could also change the foreach to this

Code:
foreach($required as $field){
    if (empty($_POST[$field])){
        $error = TRUE;
    }
    else{
        $$field = mysql_real_escape_string($_POST[$fiedl]);
    }
}

It just simply turns the POSTS into variables like you are using them :P Any post you add to the $required array is set to a variable.
So for example $_POST['bdesc'] becomes $bdesc.

On top of that it escapes the strings to be safer from SQL Injections, although I recommend using PDO for that.
http://stackoverflow.com/questions/3716373/real-escape-string-and-pdo

I used to use that when I was programming procedural a lot.

In case you don't understand the double dollar sign take a look at this:
http://www.php.net/manual/en/language.variables.variable.php

i know its prone to injections i am not using it far a site it was a homework in my php class -__-
 
Back