Hi,

I've run into absolute brickwall and am really desprate for your help please. I have a MYSQL Database with two Tables called user_comment and the second user_table. When a user register with the site, their details are kept in the user_table. the second table user_comment is so that users who are registered on the user_table can leave comments which will be passed into the user_comment table. HERE IS THE CODE FOR THE SECOND PART, CHECKING IF A USER'S EMAIL EXIST IN the user_table IF SO, PUX THESE DATA INTO user_comment TABLE. PLEASE CAN ANYONE SPOT WHAT IS WRONG WITH THE CODE???

<?php require 'db.private'; ?>
<html>
<head>
<title> Gizmo&reg; Electronics - Login</title>


</head>
<body>



<table width="100%">
<tr><td>


<?php


$connection = mysql_connect($hostname,$username,$password);
mysql_select_db($databaseName, $connection);



$submit = $_POST;
$comment = $_POST;
$email = $_POST;


if(isset($submit))  {


//if(isset($submit))    {
// check if user exists in the database
$query = mysql_query("SELECT email FROM user_table WHERE email = '".$email."'");
//$num_rows = mysql_num_rows($query_email);
//if(!$num_rows) die('Gizmerror!! Either you have typed your USERNAME and or Your PASSWORD incorrectly or you have not registered to access this pages. <p><font color="red" size="+1"><center> Please Try Again</center> </font></p>');


//mysql_query ( "INSERT INTO user_comment (email, comment) VALUES ('$email', '$comment');


$insert = "INSERT INTO user_comment SET
email = '$email',
comment = '$comment'";


//mysql_query($insert);
//$row_comment = mysql_fetch_Array($query);
die("<META http-equiv=\"Refresh\" content=\"0;url=commentdisplay.php\">");


//die("Thank you for registering.  Your Registration was Successful! You can now login");


//$insert = "INSERT INTO user_comment SET
//comment = '$comment'";


//mysql_query($insert);


die("Thank you for registering.  Your Registration was Successful! You can now login");


//}


//echo mysql_error();
//mysql_close();
}
?>


<center>



<form action="comment.php" method="post">
<table summary="comment page">


<tr>
<td><label for="comment">Your Comment:</label></td>
<td><textarea name="comment" cols="70" rows="5" wrap="VIRTUAL" id="comment" value="comment"></textarea><br /></td>
</tr>


<tr>
<td><label for="email">Email Address:</label></td>
<td><input type="text" id="email" name="email"  value="type ur email here"></td>
</tr>


<tr>
<td><input type="submit" name="submit" /></td>
</tr>


</table>
</form>


<p><a href="home.htm">...or return to our Homepage</a></p>



</td>
</tr>
</table>
</body>
</html>

THANK YOU, I REALLY APPRECIATE YOUR TIME AND EFFORT.

Dani AI

Generated

Quick diagnosis for : the script never reads individual form fields, many database calls are commented out, and the script returns/“dies” before the insert ever runs — so nothing gets written. Read POST fields as named keys (for example $_POST['email'] and $_POST['comment']) and check the request method rather than assigning the whole $_POST array to a single variable. (php.net)

Do not rely on the old mysql_* functions: they were deprecated and removed from recent PHP releases. Move to either PDO or MySQLi and use prepared statements to avoid SQL injection; prepared/parameterized queries are the recommended mitigation. Also remove the commented-out DB calls and the premature die()/redirect so the insert actually executes. (wiki.php.net)

Validate and sanitize inputs before inserting: trim() the values, enforce a sensible length on comments, and validate the email with filter_var(..., FILTER_VALIDATE_EMAIL). When sending users elsewhere after success, use a proper HTTP redirect with header('Location: ...') and exit; (headers must be sent before any output). Escape any comment text on output (e.g., htmlspecialchars) to avoid XSS. (php.net)

A minimal, modern pattern (using PDO) looks like this:

// connect (set your host/db/user/pass)
$pdo = new PDO('mysql:host=HOST;dbname=DB;charset=utf8mb4', DB_USER, DB_PASS, [
  PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
  PDO::ATTR_EMULATE_PREPARES => false,
]);

if ($_SERVER['REQUEST_METHOD'] === 'POST') {
  $email = trim($_POST['email'] ?? '');
  $comment = trim($_POST['comment'] ?? '');

  if (!filter_var($email, FILTER_VALIDATE_EMAIL)) { /* handle invalid email */ }

  $check = $pdo->prepare('SELECT 1 FROM user_table WHERE email = ? LIMIT 1');
  $check->execute([$email]);

  if ($check->fetchColumn()) {
    $ins = $pdo->prepare('INSERT INTO user_comment (email, comment) VALUES (?, ?)');
    $ins->execute([$email, $comment]);
    header('Location: commentdisplay.php'); exit;
  } else {
    /* handle "email not registered" case */
  }
}

Follow that pattern, remove the commented-out queries, and debug with error reporting turned on during development. As noted, the commented lines and early die() are the immediate showstoppers; fixing those plus the points above will get this working reliably.

Half the commands are commented...

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.