Re: Re: Forms
| From: | C.R. | Date: | Wed, 07 May 2003 14:00:32 +0000 |
| Subject: | Re: Re: Forms | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-146524@lists.php.net to get a copy of this message | ||
"And the solution is... Don't try be so lazy/cute! Specify the mysql
fields explicitly i.e."
How about efficient!. This may be a point of view, but I think the way I
have it is more efficient and easier to understand than having to sift
through a whole list of queries - and why not share forms if they are the
same - seems like a more efficient way of doing things to me. However, I
have found with PHP that efficient is not in it's vocabulary. (how will you
ever do field-specific validation?). I'm not sure about this comment as all
my forms validate fine and is done before it ever gets to this point in the
script.
Anyway, thanks for the input. At least I know the problem and can now try to
figure a way around it. If I have to type them all in, I guess I'll have
to - but this really seems to be a waste of time and effort.
----- Original Message -----
From: "George Whiffen" <george@whiffen.net>
To: <php-general@lists.php.net>
Sent: Tuesday, May 06, 2003 8:12 AM
Subject: [PHP] Re: Forms
>
>
> C.R. wrote:
> > I'm trying to use an image as a submit button in a form and getting some
> > stupid error I just can't figure out. I have four seperate forms on my
site
> > and 3 of them work and one doesn't. I have copied and pasted the input
line
> > so they are the same in all four, so I am at a loss.
> >
> > This is the line....
> >
> > <INPUT TYPE="image" src="images/arrow-r.gif" width="56"
> > height="24"
> > border="0">
> >
>
> You are specifying an image map, not just an image button. That means
> that the x,y coordinates of the mouse in "images/arrow-r.gif" when it is
> clicked are being sent as part of the form.
>
> Normally, you would specify a name for the image map e.g. <INPUT
> TYPE="image" NAME="myname", in which case the coordinates would be in
> $mynamex and $mynamey. As you have no name, the coordinates are just in
> $x and $y.
>
> Your script is trying to store these variables in your mysql table which
> is complaining that it doesn't have a field called x or y.
>
> And the solution is... Don't try be so lazy/cute! Specify the mysql
> fields explicitly i.e.
>
> replace
>
>
> > $query = "UPDATE $userinfotable SET ";
> > foreach($_POST as $field=>$value) {
> > $upfields[] = "$field='$value'";
> > }
> > $sqlfields = implode($upfields,",");
> > $query .= $sqlfields. " WHERE userid = '$userid'";
> >
>
> with
>
> $query = "UPDATE $userinfotable set
> myfield1 = '$myfield1'
> ,myfield2='$myfield2'
> ...
> WHERE userid = '$userid'";
>
> etc.
>
> I guess you wanted to only have to change your form and table when you
> add extra fields and leave the code to automatically generate the query
> from the fields specified. The problem is that you have created a
> restriction on your form i.e. it must only ever submit fields in the
> database, so you can't use TYPE="image" or extra hidden variables or
> indeed anything except fields that are definitely in your table.
>
> This is a bad idea in principle since you are creating a potentially
> fatal code/representation dependency.
>
> It really doesn't take much extra work to actually TYPE the names of the
> fields, and since you already have to change the table and the form for
> new fields it doesn't add much maintenance overhead.
>
> Or perhaps you were trying to share the php code between several
> forms/tables. Sounds pretty iffy to me, (how will you ever do
> field-specific validation?). But if you really, really want this kind
> of general technique then you should use the mysql table definition to
> cross-check the list of fields to update rather than just the list of
> POSTed variables.
>
> i.e. something like this
>
> $fieldpointer = mysql_list_fields($database,$userinfotable);
>
> while ($fieldname = mysql_fieldname($fieldpointer))
> {
> $dbfields[] = $fieldname;
> }
> and then
>
> $query = "UPDATE $userinfotable SET ";
> foreach($_POST as $field=>$value) {
>
> if (in_array($field,$dbfields)
> {
> $upfields[] = "$field='$value'";
> }
>
> }
> $sqlfields = implode($upfields,",");
> $query .= $sqlfields. " WHERE userid = '$userid'";
>
> This would work, although it will be slightly slower because of the
> overhead of picking up the mysql field list.
>
> It removes the immediate problem of image maps, but it still leaves
> representation/code dependencies. For example, you can't use your code
> to process "GET" update requests or command line (environment variable)
> requests automatically for you, since you are dependent on data coming
> via the "POST". If you try to get round that by you skipping the
> foreach ($_POST... and just using the mysql field list, you will
> probably update too much since you will be updating every field
> including userid and any timestamps or fields not in the form.
>
> So my advice is to keep it simple, and just name the fields in the
> query. In that case, your php doesn't have to know or care where the
> data came from, POST, GET, Environment, whatever. It will also be much
> easier for someone else to understand and maintain your code; more
> flexible, (you can easily add field specific processing e.g. myfield =
> '".strtoupper($myfield1."'), and less likely to break with "stupid
> errors you can't work out".
>
> Good luck,
>
>
> George
>
>
>
> > but .....this will work.
> >
> > <INPUT TYPE="submit" value="Submit">
> >
> > This is being sent to a PHP script which will then write the form info
to a
> > MySQL database - the error I am getting is this:
> >
> > Unknown column 'x' in 'field list'.
> >
> > So where is it getting the column 'x' from?
> >
> > This is the top of the form on all four forms (other than the ACTION =
and
> > FORM NAME).
> >
> > <FORM NAME="Update Profile" Target"contentFrame"
> > ACTION="editcheck.php"
> > METHOD="POST" CLASS="formstyle">
> >
> > The only thing I can think of that is causing the problem is the
following,
> > but I have no idea why. Any help is appreciated.
> >
> > $query = "UPDATE $userinfotable SET ";
> > foreach($_POST as $field=>$value) {
> > $upfields[] = "$field='$value'";
> > }
> > $sqlfields = implode($upfields,",");
> > $query .= $sqlfields. " WHERE userid = '$userid'";
> >
> >
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>