Re: problems with strchr...

From: Date: Tue, 05 Sep 2000 03:17:06 +0000
Subject: Re: problems with strchr...
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15218@lists.php.net to get a copy of this message
Juan Luis Baptiste M. writes: > I have a function to verify if a string has invalid characters or not, > this is the function: > > function verifyUser($login) > { > // $login=stripslashes($login); > $n= strlen($login); > if (($n >= 4) && ($n <= 12)) > if ((strchr($login,'!')!=false) && > (strchr($login,'"')!=false) > } [trim] > If I pass the string 'minickn@me' it always return true. I don't know if > the problem is my code (I suppose) or strchr, but if someone can help me > > with this thanks. > > -- > ------------------------------------- > Juan Luis Baptiste M. The main problem is that there are so many tests and test levels that it gets hard to read the code & follow what's going on. You can probably reduce the whole thing down to something like this: function verifyUser($login) { $login = stripslashes($login); $n = strlen($login); if ($n < 4 || $n > 12) { return false; } return ereg('[^A-Z0-9_]+', $login) ? -1 : true; } If you don't get the last line, it means the same thing as: if (eregi('[^A-Z0-9_]+', $login)) { return -1; } else { return true; } ...see http://www.php.net/manual/language.operators.comparison.php for more information on <expr> ? <expr> : <expr>. Anyway, when you're testing for invalid characters, it's often a better idea not to. :) Instead, test for only valid characters: that way, you don't need to ensure that you've thought of every possible invalid character. All you need to know is the ones which *are* valid. Saves a bunch of fixing later. One more problem in the code given was that strchr() returns 0 if the character is found in the first position of $login. This is because PHP counts string offsets starting from zero, not from one. This is a problem here because 0 evaluates to false in PHP, giving results you wouldn't expect. Also, all the '&&' should be '||'. And'ing the results means that it would only trip on a string which included *all* of the invalid characters. For an explanation of the regular expression used to check the characters, check out the ereg() documentation at: http://www.php.net/manual/ref.regex.php That page also contains a pointer to a man page which explains regular expression syntax. In short, the regex '[^A-Z0-9_]+' mean 'Match anything which isn't an alphabetic character, digit, or underscore, and which occurs at least once'. You'll need to fiddle with the A-Z0-9_ bit to get it to include all of your valid characters. Hope this helps, Torben -- +----------------------------------------------------------------+ |Torben Wilson <torben@php.net> Netmill iTech| |http://www.coastnet.com/~torben http://www.netmill.fi| |Ph: 1 250 383-9735 torben@netmill.fi| +----------------------------------------------------------------+

« previous php.general (#15218) next »