Re: OT? passing text variables through html forms.
| From: | Teodor Cimpoesu | Date: | Fri, 30 Jun 2000 01:12:39 +0000 |
| Subject: | Re: OT? passing text variables through html forms. | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-3933@lists.php.net to get a copy of this message | ||
Hi Kris!
On Thu, 29 Jun 2000, Kris Dahl wrote:
> >> $var = "This is 'a' test";
> >> <input type='hidden' name='name' value='$var'>
> >> ?>
> > try
> > <input type='hidden' name='name'
> > value='<?=rawurlencode($var)?>'>
> > or
> > <? echo "<input type='hidden' name='name'
> > value='" . rawurlencode($var)."'>";
> > ?>
> > so on
> > AFAIK ' and " are not allowed in urls, so they will be translated and I expect
> > PHP to decode it as any url-encoded content, or you may call rawurldecode() on
> > the other end.
>
> This is true that spaces aren't allowed, but the form is automatically
> urlencoded when submitted, so that won't be the problem nor the solution.
Hmm, maybe I got it wrong, but I was referring to something like
$passphrase = "\"'Open the door,you naughty kids!' said the gatekeeper\" --
Keystone";
[server]
<form ...>
<input type='hidden'
name='pf'
value='<%=$passphrase%>'>
...
</form>
[client - printed var]
<form ...>
<input type='hidden'
name='pf'
value='"'Open the door,you naughty kids!' said the gatekeeper" --
Keystone'>
...
</form>
[client - urlencoded var]
<form ...>
<input type='hidden'
name='pf'
value='%22%27Open%20the%20door%2Cyou%20naughty%20kids%21%27%20said%20the%20gatekeeper%22%20--%20Keystone'>
...
</form>
So the encoding/escaping has to be done *before* sending the form fields to
the client, else you'll end up in broken value attribute because of its content.
-- teodor