Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #1783

Re: You have an error in your SQL syntax;

From Jerry Stuckle <jstucklex@attglobal.net>
Newsgroups comp.lang.php
Subject Re: You have an error in your SQL syntax;
Date 2011-05-22 17:16 -0400
Organization A noiseless patient Spider
Message-ID <irbugb$6uc$1@dont-email.me> (permalink)
References <1b4559f6-a3bc-4a87-95e1-adefc83b7286@a10g2000vbz.googlegroups.com> <4dd943d1$0$49177$e4fe514c@news.xs4all.nl> <ab86cb26-0606-483d-8866-fdf54974c8e7@32g2000vbe.googlegroups.com> <4dd97380$0$49044$e4fe514c@news.xs4all.nl> <cc3fadf4-cdc3-41e0-a26a-0e0d4e367be8@q30g2000vbs.googlegroups.com>

Show all headers | View raw


On 5/22/2011 4:56 PM, Co wrote:
> On 22 mei, 22:35, Luuk<L...@invalid.lan>  wrote:
>> On 22-05-2011 22:11, Co wrote:
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>> On 22 mei, 19:11, Luuk<L...@invalid.lan>  wrote:
>>>> On 22-05-2011 16:01, Co wrote:
>>
>>>>> Hi all,
>>
>>>>> I run a query based on the input in a listbox.
>>>>> The query looks for users from a certain country.
>>>>> When no users are from the chosen country I get a error message.
>>>>> Is there no way to check if there are records in the query before
>>>>> trying to output
>>>>> so we only get a message saying: No records for this search.... or
>>>>> something like it.
>>
>>>>> Regards
>>>>> Marco
>>
>>>> I hope you know that there is a great MANUAL online at:http://www.php.net
>>
>>>> It has this great info:http://php.net/manual/en/function.mysql-num-rows.php
>>
>>>> --
>>>> Luuk
>>
>>> Thanks Luuk,
>>> I didn't know.
>>> Anyways I tried an example from the page:
>>
>>> $num_rows = mysql_num_rows($sql2);
>>> if($num_rows<>  0) {
>>> while($row = mysql_fetch_array($sql2)) { ......
>>
>>> else {
>>> print ("<p>No records for this search were found.</p>");
>>> }
>>
>>> But I still get the error line saying:
>>> Warning: mysql_num_rows(): supplied argument is not a valid MySQL
>>> result resource
>>
>>> Marco
>>
>> The argument to mysql_num_rows() should not be a sql-statement, so
>> sending a parameter with the name $sql2 seems confusing
>>
>> The argument you need to pass is the result from mysql_query();
>>
>> like the example:
>> $result = mysql_query("SELECT * FROM table1", $link);
>> $num_rows = mysql_num_rows($result);
>>
>> --
>> Luuk
>
> Guys,
>
> I solved it.
> I put this in the beginning:
> $nr = mysql_num_rows($sql); // Get total of Num rows from the database
> query
> if ($nr){  // if we found any records we will proceed
>
> If the query returns 0 records we pass all the code and just say "No
> records found".
>
> The only problem I still have is when I load the page first time I get
> an error saying:
> Notice: Undefined index
> Somehow on this line:
>
> if (($_POST['listByq'] == "newest_members")) {
>
> listByq has not been defined.
> Can I declare it at the top of the page?
>
> Marco

You can declare it, but rather you should use:

if (isset($_POST['listByq']))
   $listByq = $_POST['listByq'];
else
   $listByq = 'Some default value'; // Use an appropriate value

Which can also be shortened to:

$listByq = isset($_POST['listByq']) ? $_POST['listByq'] : 'Some default 
value';

Then use $listByq from there on.

And BTW - ALWAYS validate any input from the user, including $_POST 
values.  There is no guarantee these values came from your form, for 
instance.  A hacker can easily provide whatever value he wants.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

You have an error in your SQL syntax; Co <vonclausowitz@gmail.com> - 2011-05-22 07:01 -0700
  Re: You have an error in your SQL syntax; Luuk <Luuk@invalid.lan> - 2011-05-22 19:11 +0200
    Re: You have an error in your SQL syntax; Co <vonclausowitz@gmail.com> - 2011-05-22 13:11 -0700
      Re: You have an error in your SQL syntax; The Natural Philosopher <tnp@invalid.invalid> - 2011-05-22 21:21 +0100
      Re: You have an error in your SQL syntax; Jerry Stuckle <jstucklex@attglobal.net> - 2011-05-22 16:21 -0400
      Re: You have an error in your SQL syntax; Luuk <Luuk@invalid.lan> - 2011-05-22 22:35 +0200
        Re: You have an error in your SQL syntax; Co <vonclausowitz@gmail.com> - 2011-05-22 13:56 -0700
          Re: You have an error in your SQL syntax; Jerry Stuckle <jstucklex@attglobal.net> - 2011-05-22 17:16 -0400
            Re: You have an error in your SQL syntax; Co <vonclausowitz@gmail.com> - 2011-05-22 14:22 -0700

csiph-web