Re: Re: opening pdf file in new window with a POST operation
| From: | Tom Rogers | Date: | Fri, 05 Jul 2002 05:16:40 +0000 |
| Subject: | Re: Re: opening pdf file in new window with a POST operation | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-105567@lists.php.net to get a copy of this message | ||
Hi
get data is insecure by nature so the whole page is insecure and no warnings, as soon as you post you invoke the security. You probably have a url on your page that is coming from an insecure server (http:// instead of https://)
Tom
At 11:01 PM 4/07/2002 -0600, Peter James wrote:
----- Original Message ----- From: "Richard Lynch" <rich@phpbootcamp.com> Newsgroups: php.general To: <php-general@lists.php.net> Sent: Thursday, July 04, 2002 3:28 PM Subject: Re: opening pdf file in new window with a POST operation<form action="https://my.server/reports.php" method="post" target="_blank"> <input type=submit value='Show PDF'> </form> <form action="https://my.server/reports.php" method="get" target="_blank"> <input type=submit value='Show PDF'> </form> These forms are identical with the exception of the post/get methods. A PDF file is being dynamically generated and displayed in a pop-up. The GET method form works fine, while the POST method (which is what I need to use) pops up a message about the page containing both secure and nonsecure data. WTF?Well, the new browser window opens, but you're loading a PDF, not HTML, so it's not really getting any data at all. The data it's not getting isn't secure, by definition, since there's nothing there. I'm not sure that I understand what you're saying here... I'm loading a php file, that is creating the pdf on-the-fly. This php file is the one receiving the POST data, not the window - or do I not understand? BTW... This example is not how the application works. It's just a test that I used to narrow down the problem, and recreate in a controlled situation. The real application needs to have the pdf file pop up in a separate window using POST vars, which, in the application, is done using Javascript - but I digress... How is the POST data not 'secure' but the GET data is? How is it not secure 'by definition'? There's nothing where? Please expand. Thanks for you response, Pete. -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php