Re: Re: Forms

From: Date: Tue, 06 May 2003 14:43:52 +0000
Subject: Re: Re: Forms
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-146528@lists.php.net to get a copy of this message
> How about efficient!. This may be a point of view, but I think the way I > have it is more efficient and easier to understand than having to sift > through a whole list of queries - and why not share forms if they are the > same - seems like a more efficient way of doing things to me. However, I > have found with PHP that efficient is not in it's vocabulary. (how will you > ever do field-specific validation?). I'm not sure about this comment as all > my forms validate fine and is done before it ever gets to this point in the > script. How are you doing validation? With PHP or Javascript? There's nothing wrong with your method, but it's harder to maintain as a change in one area must be supported with a change in another. For instance, if you add a field to your form, you must now add it to your database or you must strip out the value before you "create" your SQL. So your presentation affects your logic, instead of the two being separate. If you explicity wrote out your query, then changes in your form or presentation wouldn't affect the PHP code with your query. Either way, as long as your validating everything prior to this on the server side, use whatever method you want. I always place all of my validated variables into another array. You could then use your method on this new array. The reason I do this is so that I only use validated variables in queries, output, and links later in the code. I don't use the $_GET, $_POST variables directly as they may be tainted. ---John Holmes...

« previous php.general (#146528) next »