Re: complicated questions
| From: | Manuel Lemos | Date: | Mon, 07 Aug 2000 22:51:43 +0000 |
| Subject: | Re: complicated questions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-10591@lists.php.net to get a copy of this message | ||
Hello Daniel,
On 07-Aug-00 11:56:00, you wrote:
>> It seems to me that the best way to do it is to validate this on the
>> client-side
>> (i.e. JavaScript) and not on the server-side (i.e. PHP).
>Doing anything on the client side is a poor idea. Web programmers can't
>control the client setup. First, if the client isn't running Java Script,
>the site you spent so much time and money developing becomes worthless to
>that user. Second, if the person on the client side decides to mess with
>you, they can save the form, rip out the Java Script and submit a form with
>invalid data in it.
>Trusting the client side to do anything is not wise.
Client side validation can and should be used as a complement of server
side validation to avoid server round trip and other problems like annoying
the user with delays to tell something in the form is not right. Server
side validation should always be performed.
You may want to try this PHP class that generates the necessary Javascript
code to perform several types of built-in validations and can also do the
same validations on the server side. As a bonus you also have facilities to
avoid other annoyances like optionally preventing a form to be submitted
inadvertdly, activating form fields for keyboard input among many other
features.
http://phpclasses.UpperDesign.com/browse.html/package/1
Regards,
Manuel Lemos
Web Programming Components using PHP Classes.
Look at: http://phpclasses.UpperDesign.com/?user=mlemos@acm.org
--
E-mail: mlemos@acm.org
URL: http://www.mlemos.e-na.net/
PGP key: http://www.mlemos.e-na.net/ManuelLemos.pgp
--