1
corne
Wrong query??
  • 2005/3/3 9:56

  • corne

  • Just popping in

  • Posts: 24

  • Since: 2005/1/12


I have added the following to userinfo.php:

le="color: #000000"><?php if(isset($HTTP_GET_VARS['usr'])){ //get UID from database $uid_get_query = 'SELECT uid FROM '.$xoopsDB->prefix('users').' WHERE uname='.$HTTP_GET_VARS['usr']; $uid_get_result = $xoopsDB->query($uid_get_query); while($uid_get = $xoopsDB->fetchArray($uid_get_result)) { $uid = $uid_get[0]; } }


It should be possible to goto http://www.yoursite.tld/userinfo.php?usr=uname
to get the profile...

But $uid stays empty (also when the user exists)
What is wrong with this query or what is wrong with the code??

I can't seem to find out why this doesn't work...

2
Mithrandir
Re: Wrong query??

Either use $xoopsDB->fetchArray() and $uid_get['uid']
or $xoopsDB->fetchRow() and $uid_get[0]

3
Dave_L
Re: Wrong query??
  • 2005/3/3 11:20

  • Dave_L

  • XOOPS is my life!

  • Posts: 2277

  • Since: 2003/11/7


Some other things:

$_GET should be used instead of $HTTP_GET_VARS.
The username should be sanitized prior to using it in a query.
The username needs to be in quotes.

le="color: #000000"><?php $uid = 0; if (isset($_GET['usr'])){ $uname_q = MyTextSanitizer::addSlashes($_GET['usr']); $result = $xoopsDB->query( 'SELECT uid FROM ' .$xoopsDB->prefix('users'). " WHERE uname='$uname_q'" ); $row = $xoopsDB->fetchArray($result); $xoopsDB->freeRecordSet($result); $uid = ($row !== false) ? $row['uid'] : 0; }

Login

Donat-O-Meter

Stats
Goal: $15.00
Due Date: Jul 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $15.00
Make donations with PayPal!

Latest GitHub Commits