Re: Need data to persist through call to self

From: Date: Sat, 02 Dec 2000 21:10:37 +0000
Subject: Re: Need data to persist through call to self
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-28391@lists.php.net to get a copy of this message
On Sat, 2 Dec 2000, Jeffrey Blaze wrote: > I have a script (a.php) that collects selection criteria from the user, and > passes it and other arguments (via POST) to another script (b.php). B.php > uses this passed data to lovingly craft and submit a MySQL statement. The > returned data is displayed, the script displays data to the user, and asks > if he/she wishes to re-sort it. If so, he/she clicks a link, which re-calls > the same script. > > The problem: The data passed by a.php to b.php is no longer available. I > can't use POST, because the user is not submitting a form to re-sort the > data; he/she is clicking a link. Also, because I am not using a form, I > cannot use HTML hidden variables. I can't use GET, because the SELECT > statement is too long to append to the URL (I wouldn't want to put it there, > anyway). > > What should I do? Save the original selection criteria in a flat file, or > in a table? Save the originally selected data in a temporary table? Seems > in-elegant, and wouldn't I need to identify this file or table with a > session ID? > Why are you sending a query between scripts? That leaves a HUGE security hole in your system. What you should be doing is passing key values from a.php to b.php via GET (these are just SELECT statements, right?) and then have b.php do the SQL statement generation. That way you can have b.php pass the values to itself without problem. That's the way I did it, and it works flawlessly. -- Ignacio Vazquez-Abrams <ignacio@openservices.net>

« previous php.general (#28391) next »