Re: OT? passing text variables through html forms.

From: Date: Fri, 30 Jun 2000 01:12:39 +0000
Subject: Re: OT? passing text variables through html forms.
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-3933@lists.php.net to get a copy of this message
Hi Kris! On Thu, 29 Jun 2000, Kris Dahl wrote: > >> $var = "This is 'a' test"; > >> <input type='hidden' name='name' value='$var'> > >> ?> > > try > > <input type='hidden' name='name' > > value='<?=rawurlencode($var)?>'> > > or > > <? echo "<input type='hidden' name='name' > > value='" . rawurlencode($var)."'>"; > > ?> > > so on > > AFAIK ' and " are not allowed in urls, so they will be translated and I expect > > PHP to decode it as any url-encoded content, or you may call rawurldecode() on > > the other end. > > This is true that spaces aren't allowed, but the form is automatically > urlencoded when submitted, so that won't be the problem nor the solution. Hmm, maybe I got it wrong, but I was referring to something like $passphrase = "\"'Open the door,you naughty kids!' said the gatekeeper\" -- Keystone"; [server] <form ...> <input type='hidden' name='pf' value='<%=$passphrase%>'> ... </form> [client - printed var] <form ...> <input type='hidden' name='pf' value='"'Open the door,you naughty kids!' said the gatekeeper" -- Keystone'> ... </form> [client - urlencoded var] <form ...> <input type='hidden' name='pf' value='%22%27Open%20the%20door%2Cyou%20naughty%20kids%21%27%20said%20the%20gatekeeper%22%20--%20Keystone'> ... </form> So the encoding/escaping has to be done *before* sending the form fields to the client, else you'll end up in broken value attribute because of its content. -- teodor

« previous php.general (#3933) next »