Re: PHP_SELF

From: Date: Fri, 03 Aug 2001 05:42:30 +0000
Subject: Re: PHP_SELF
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-61082@lists.php.net to get a copy of this message
> if(!$Age) { echo "Please enter your age"; } > elseif(!$Email){ echo "Please enter your email"; } > else > echo "Thanks for your submission"; > // continue processing... > } *ACTUALLY*, it's rather annoying to have a web-site tell you one field at a time what you have filled in wrong as you click Submit over and over and over... *ESPECIALLY* if they don't pre-inform you of what is/isn't valid input! Sidebar: If you're going to restrict what input is acceptable, inform the user in fine print what's allowed! This includes claiming Zip+4 is invalid, you goofs. Sidebar: For a username, could you at *LEAST* let me use my email for a username so (A) it will be not "already used" and (B) I have a *CHANCE* of remembering it when I come back?! I have to run through 20 different possiblities for some sites I use semi-regularly when I log in. Other sites I never use simply because I know I can't remember my username for that site. Here's a slightly better design: <?php $message = ''; if (isset($submit)){ # The NAME= from your TYPE=SUBMIT button if (!$Age){ $message .= "You must enter a valid age in years<BR>\n"; } if (!$Email){ $message .= "You must enter a valid email<BR>\n"; } } if (!$message){ # Process valid input } else{ ?> <FORM ... > <?php echo "<FONT COLOR=FF0000>$message</FONT>";?> Age: <INPUT NAME=Age ...> . . . </FORM> Sidebar: You could go a lot further in validating the $Email. You could even type in a three (3) page Regular Expression from the back of the Camel book and be completely RFC-compliant... If you didn't mind the fact that it will probably be dog-slow and very RAM-intensive. There are a bazillion email-checking Regexes posted to the 'Net. Many of them will reject perfectly valid emails :-( You need one that will maybe let a bad email slip by, but will *NOT* reject any valid addresses. Good luck finding one. No, I don't know where one is. You could also use some PHP functions (SNMP?) to look up the MX record for the domain name of the email, and ask that MX server if it accepts that email as valid... Only some MX servers will just say "Yeah, sure" for invalid emails, and some will refuse to answer at all, and some will just plain out-and-out lie and say an email is invalid when it's fine. So, bottom line, if you *really* care about having a valid email, you have to send a secret randomly-generated unique registration code required to complete the registration to the address to force the user to provide a working email. Of course, there's nothing to stop them from creating a Yahoo (et al) email and checking it only once to get the registration code, and never, ever, ever using that email address again for anything. So, in the end, there's really not a whole lot of point to doing all that, is there?... It boils down to: "How important is it to you that they give you an email that might only be valid for a few hours? Maybe you shouldn't require it at all." YMMV. -- WARNING richard@zend.com address is an endangered species -- Use ceo@l-i-e.com Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm Volunteer a little time: http://chatmusic.com/volunteer.htm

« previous php.general (#61082) next »