For a new poll, keep the question ID and submitted choice as server-validated values. Use prepared statements for every database lookup and do not rely on a raw session ID as the only protection against repeated voting.
<?php
session_start();
$qstId = 1;
$stmt = $pdo->prepare(
'SELECT qst, opt1, opt2, opt3, opt4 FROM plus_poll WHERE qst_id = :id'
);
$stmt->execute(['id' => $qstId]);
$poll = $stmt->fetch(PDO::FETCH_ASSOC);
if (!$poll) {
http_response_code(404);
exit('Poll not found');
}
?>
For public polls, add a CSRF token, a server-side participation record or rate limit, and a clear privacy policy if you store identifiers such as account IDs or IP-derived data. The original session-based tutorial remains below because it explains the basic workflow.
session_start();
$s_id=session_id();
require "config.php";
//////////////////////////////
/* Read the session id to
display the poll result link
*/
$count=$dbo->prepare("select s_id from plus_poll_ans where s_id='$s_id'");
$count->execute();
$no=$count->rowCount();
//echo $no;
if($no <=0 ){
echo "<a href=view_poll_result.php>View the poll result</a>";
}
/* You can keep the parts below inside the else area if you don't want to
show the form for the visitors who have already participated in the poll
*/
$qst_id=1; // Change this ID for a different poll
$count=$dbo->prepare("select * from plus_poll where qst_id=:qst_id");
$count->bindParam(":qst_id",$qst_id,PDO::PARAM_INT,1);
if($count->execute()){
//echo " Success <br>";
$query = $count->fetch(PDO::FETCH_OBJ);
}
//$query=mysql_fetch_object(mysql_query("select * from plus_poll where qst_id=$qst_id"));
echo "
<form method=post action=poll_displayck.php>
<input type=hidden name=qst_id value=$qst_id>
<table border='1' cellspacing='0' bordercolor='#ffff00' width='320' id='AutoNumber1'>
<tr>
<td width='100%' bgcolor='#ffff00'><font face='Verdana' size='2' >$query->qst</font></td>
</tr>
<tr>
<td width='100%' >
<table border='0' cellspacing='0' bordercolor='#111111' width='100%' cellpadding='0'>
<tr bgcolor='#f1f1f1'>
<td width='10%'><input type='radio' value='$query->opt1' name='opt'></td>
<td width='90%'><font face='Verdana' size='2' >$query->opt1</font></td>
</tr>
<tr>
<td width='10%'><input type='radio' value='$query->opt2' name='opt'></td>
<td width='90%'><font face='Verdana' size='2' >$query->opt2</font></td>
</tr>
<tr bgcolor='#f1f1f1'>
<td width='10%'><input type='radio' value='$query->opt3' name='opt'></td>
<td width='90%'><font face='Verdana' size='2' >$query->opt3</font></td>
</tr>
<tr>
<td width='10%'><input type='radio' value='$query->opt4' name='opt'></td>
<td width='90%'><font face='Verdana' size='2' >$query->opt4</font></td>
</tr>
</table>
</td>
</tr>
<tr>
<td width='100%' bgcolor='#ffff00' align=center>
<font face='Verdana' size='2' ><input type=submit value=Submit></form></td>
</tr>
</table>
";
/* End of the form displaying the poll question and its four options for selection */
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.