tags:

views:

68

answers:

2

Hi, I am using a form to get the input of username and password to store the value into the database, once the form is submitted i have defined a table to show all the values from the users table, it have 3 fields (id, name, pass) i want to delete each record by it's id .

i am fetching the data from the users table by using the following code:

while($row = mysql_fetch_assoc($result_select)) {
           echo "<tr>";
           echo "<td>" . $row['id'] . "</td>";
           echo "<td>" . $row['name'] . "</td>";
           echo "<td>" . $row['pass'] . "</td>";
           echo "</tr>"; }

i want to add the delete hyperlink to delete the particular records by id.

i tried using the following code and i couldnt achieve it.

if(mysql_num_rows($result_select) > 0) {

        if(isset($_POST['id'])) {
             $query_delete = "DELETE FROM users WHERE id =" .$_POST['id']; 
             $result_delete = mysql_query($query_delete);

        }
       echo "<table cellpadding=10 border=1>";
        while($row = mysql_fetch_assoc($result_select)) {

           echo "<tr>";
           echo "<td>" . $row['id'] . "</td>";
           echo "<td>" . $row['name'] . "</td>";
           echo "<td>" . $row['pass'] . "</td>";
           echo "<td><a href=".$_SERVER['PHP_SELF']."?id=".$row[id].">Delete</a></td>"; 
           echo "</tr>";
        }
  echo "</table>";
    }

I am a newbie to programming, i would appreciate if someone explain me in simple words.. thank you :)

A: 

You need to change $_POST to $_GET, so this should work.

if(isset($_GET['id'])) {
    $query_delete = "DELETE FROM users WHERE id =" .$_GET['id']; 
    $result_delete = mysql_query($query_delete);

and also put values of attributes inside double quotes, like this

echo '<td><a href="'.$_SERVER['PHP_SELF'].'?id='.$row[id].'">Delete</a></td>';
Hamid Nazari
I really don't recommend using GET for delete operations. The user might accidentally access the URL and you'll have unwanted deletes.I believe also W3C doesn't recomment GET for modifing actions (insert/update/delete). Use it only for displaying data ;)
Bogdan
And if you really have to, at least do an intval() on the argument. Better is to use PDO for database connections and work with binding.
Blizz
what method would you use then to delete the records? is it not possible to delete the records with $_POST??
Ibrahim Azhar Armar
The recommendation is as Bogdan said: $_GET is only used for data retrieval, $_POST is used for modification. It's just a guideline, but it keeps things structured. Given the proper safety precautions you can of course delete records using data from $_GET, it's just not common practice :)
Blizz
if $_POST is used for modification then i should be able to delete the record using this rite?
Ibrahim Azhar Armar
Ibrahim I think you are missing the point. The $_GET and $_POST are used to get data in your application which records you actually want to delete. To delete the records you can use the code presented by Hamid, but you need to sanitize it first: intval($_GET['id']) for example, to force it to be a number.
Blizz
thank you i got your point.. however i have a confusion here.. <a href="'.$_SERVER['PHP_SELF'].'?id='.$row[id].'">i get two understand the $_SERVER['PHP_SELF'] and $row['id'] but i am unable to understand '?id' can you please explain the statement?thanks
Ibrahim Azhar Armar
The ?id in your code accessible with $_GET['id'] as it is a variable set via the URL. That is how Hamid used it as well. The $_SERVER['PHP_SELF'] is not needed. It is perfectly okay to link to ?id=<number> if you are calling the same script
Blizz
+1  A: 

First of all put your delete code in your page like this:

   if(isset($_POST['submit'])) {

         for($i = 0; $i < count($_POST['del']); $i++)
         {
           // check which records to delete
           if (isset($_POST['del'][$i]))
           {
             $query_delete = "DELETE FROM users WHERE id = " . (int) $_POST['del'][$i];
             $result_delete = mysql_query($query_delete) or die(mysql_error());
           }
         }

         echo 'Record Deleted !!' . '<br /><br />';
    }

Later put your select code and modify it like this:

echo '<form action="" method="POST">';
while($row = mysql_fetch_assoc($result_select)) {
       echo "<tr>";
       echo "<td>" . $row['id'] . "</td>";
       echo "<td>" . $row['name'] . "</td>";
       echo "<td>" . $row['pass'] . "</td>";
       echo "<td><input type=\"checkbox\" name=\"del[]\"></td>";
       echo "</tr>";
}
echo '<input type="submit" name="submit">';
echo '</form>';
Sarfraz
thank you, i was searching for this piece of information.
Ibrahim Azhar Armar
Hi sAc, thank you for pointing this out, this was just the second question of mine to the forum as i joined before two days and i was unaware of the rules and regulations. thank you very much once again for the response.
Ibrahim Azhar Armar
@Ibrahim Azhar Armar: You are welcome :)
Sarfraz