• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 83
  • Last Modified:

What is wrong with this update statement?

Here's my code:

$jorja="update features set featurename='$_POST[feature_name_'.$vivian_row[id]]' where id=$vivian_row['id']";

The error I get is "Parse error: syntax error, unexpected '' (T_ENCAPSED_AND_WHITESPACE), expecting ']' in C:\wamp\www\kitchen\adm\features_edit.php on line 20"

I don't see what the problem is...
0
brucegust
Asked:
brucegust
4 Solutions
 
brucegustPHP DeveloperAuthor Commented:
I made this change:

$jorja="update features set featurename='$_POST[feature_name_'.$vivian_row['id'].']' where id='$vivian_row[id]'";

Same error.

What?
0
 
Guy Hengel [angelIII / a3]Billing EngineerCommented:
$jorja="update features set featurename='" . $_POST['feature_name_'.$vivian_row[id]] ."' where id=$vivian_row['id']";
0
 
Scott Fell, EE MVEDeveloperCommented:
NO POINTS

While I am sure Guy's code is good and meets your needs for the purpose of this question, you should really sanitize your data before updating.    Updating or adding raw posted and concatenated data to your database is not very safe.

At the very least, sanitize http://php.net/manual/en/filter.filters.sanitize.php and use an abstraction if you are not already http://php.net/manual/en/intro.pdo.php


$feature_name = $_POST[feature_name];
$new_feature_name = filter_var($feature_name , FILTER_SANITIZE_STRING).$vivian_row[id];
$jorja="update features set featurename='" . $new_feature_name  ."' where id=$vivian_row['id']";
1
Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

 
Ray PaseurCommented:
There are several problems here, but nothing that can't be simplified and corrected easily.

If you're making reference to $_POST in a query string it almost certainly means your script is vulnerable to external attacks.  You probably want to use MySQLI::real_escape_string() or a similar "minimum-level" method to sanitize the external data.

If you're using an associative array index without quotation marks, you're at risk that a defined constant could cause a name collision, and in any case, your code will raise an unwanted Notice message.  Learn more about how PHP quotes and apostrophes work here.
https://www.experts-exchange.com/articles/12241/Quotation-Marks-in-PHP.html

If you're using compound statements, you're writing code that is brittle and hard to debug.  This is probably the source of the parse error -- it's difficult to see where the quote marks are supposed to go in compound statements and arguments.  So just don't do that!  You can make this easier on yourself by writing simple, unit-level statements.  Please see AntiPractices 9 and 9a.

Here is how I might do it.  You can create different variables, and each of these variables can be fed to var_dump() so you can see what the variable(s) contain.  Much easier than guessing whether your syntax is correct!  For links to the PHP var_dump() man page, please refer back to your recent questions.
// ISOLATE vivian_row id 
$vrid    = $vivian_row['id'];
$ok_vrid = $mysqli->real_escape_String($vrid);

// ISOLATE POST-REQUEST feature_name_
$pfid    = 'feature_name_' . $vrid;
$ok_pfid = $mysqli->real_escape_String($pfid);

// CONSTRUCT THE QUERY -- DO YOU WANT A TABLE SCAN, OR SHOULD YOU CONSIDER USING A "LIMIT 1" CLAUSE??
$jorja   = "UPDATE features SET featurename='$ok_pfid' WHERE id='$ok_vrid'";

Open in new window

0
 
Vatsal ShahFull Stack Expert Web DeveloperCommented:
Please Try Below Code.
$jorja="update features set featurename={$_POST['feature_name_'.$vivian_row['id']]} where id=".$vivian_row['id'];

Open in new window


Regards,
Vatsal
0
 
Ray PaseurCommented:
To anyone coming across this in the future, the "assisted solution" from Vatsal Shah perpetuates one of the many dangerous practices that novice PHP programmers often follow without understanding the risks.  

Do not use unfiltered values from any external variable (in this case $_POST) in a query string.
1
 
Vatsal ShahFull Stack Expert Web DeveloperCommented:
Hey Ray Paseur,

Yes, You are Right to not to send anything directly from user.
But here the issue was with update query, so just gave him solution.
Otherwise it is common practice to validate, sanitize, etc.

Thanks.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now