Re: PHP 4.0 Bug #6124: Transparent SID adds to the form action, instead of adding a hidden field
| From: | chrisv at b0rked dot dhs dot org | Date: | Sat, 12 Aug 2000 18:18:47 +0000 |
| Subject: | Re: PHP 4.0 Bug #6124: Transparent SID adds to the form action, instead of adding a hidden field | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-28706@lists.php.net to get a copy of this message | ||
> Does no one else see my point? REQUEST_METHOD tells you which way data's
> coming at you (get, post, or the other one..) so to me it's a pretty strong
REQUEST_METHOD may tell you which way the data is coming at you from, but,
at least to my knowledge, there is no restriction to using GET parameters
within a POST uri. And, if you know you're only checking for a single
parameter in the query string, as I'm sure has been said many times
already, what's so difficult about doing it?
> indication that you're only supposed to use one method at a time. Putting
> in a hidden field is an elegant solution that will work in *all* cases.. so
> why the fuss?
Putting in a hidden field is a solution which will break a LOT of
javascript to bits and pieces. Take this piece of code, for example:
<script language="JavaScript">
var OriginalValues = new Array('1', '2', '3', '4');
function loadValues() {
for (i = 0; i < OriginalValues.length; i++) {
document.forms[0].elements[i].value = OriginalValues[i];
}
}
</script>
<body onload="loadValues()">
<form action="myhandler.php" method="POST">
<input type=text name="Value1"><input type=text
name="Value2"><input
type=text name="Value3"><input type=text name="Value4">
</form>
</body>
It's a simple example, but if PHP were to insert the hidden field, there
is a high possibility that the piece of code you see there would break.
Adding the SID to the form action doesn't mess anything up.
Chris