Re: Form Input Type

From: Date: Thu, 09 Nov 2000 10:55:38 +0000
Subject: Re: Form Input Type
References: 1 2 3 4  Groups: php.db 
Request: Send a blank email to php-db+get-4328@lists.php.net to get a copy of this message
Michael Dearman wrote: > > Jorge Alvarez wrote: > > > > > > Is it possible that I could specify the data type of the field inside > > the > > > > FORM, like <Input Type="character or number only" ....> > > > > something like > > that? > > > > No, this is not possible. Forms are HTML-based objects and HTML itself does > > not have validation capabilities. > > > > But that's not a problem at all. You could use JavaScript to validate the > > form on the client side, *before* it is sent to the PHP-enabled web server. > > This form data could still regarded as 'user input'; thus possibly > tainted. I look at javascript validation as a service provided by the client. Fast > repsonse on improper input. But there probably should still be server side re-validation > of user input. > > Mike D. > > -- > PHP Database Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net > For additional commands, e-mail: php-db-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net There must be server side validation! I can rewrite the Header reponse to provide whatever information I want to push into the server's awaiting web page/URL address. Javascript is based on an "Honor System" of data integrity. If you are looking for the real deal, then you have to be able to validate where the customer cannot reach

« previous php.db (#4328) next »