Re: Re: Forms
| From: | CPT John W. Holmes | Date: | Tue, 06 May 2003 14:43:52 +0000 |
| Subject: | Re: Re: Forms | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-146528@lists.php.net to get a copy of this message | ||
> How about efficient!. This may be a point of view, but I think the way I
> have it is more efficient and easier to understand than having to sift
> through a whole list of queries - and why not share forms if they are the
> same - seems like a more efficient way of doing things to me. However, I
> have found with PHP that efficient is not in it's vocabulary. (how will
you
> ever do field-specific validation?). I'm not sure about this comment as
all
> my forms validate fine and is done before it ever gets to this point in
the
> script.
How are you doing validation? With PHP or Javascript?
There's nothing wrong with your method, but it's harder to maintain as a
change in one area must be supported with a change in another.
For instance, if you add a field to your form, you must now add it to your
database or you must strip out the value before you "create" your SQL. So
your presentation affects your logic, instead of the two being separate.
If you explicity wrote out your query, then changes in your form or
presentation wouldn't affect the PHP code with your query.
Either way, as long as your validating everything prior to this on the
server side, use whatever method you want.
I always place all of my validated variables into another array. You could
then use your method on this new array. The reason I do this is so that I
only use validated variables in queries, output, and links later in the
code. I don't use the $_GET, $_POST variables directly as they may be
tainted.
---John Holmes...