Re: PHP_SELF
| From: | Richard Lynch | Date: | Fri, 03 Aug 2001 05:42:30 +0000 |
| Subject: | Re: PHP_SELF | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-61082@lists.php.net to get a copy of this message | ||
> if(!$Age) { echo "Please enter your age"; }
> elseif(!$Email){ echo "Please enter your email"; }
> else
> echo "Thanks for your submission";
> // continue processing...
> }
*ACTUALLY*, it's rather annoying to have a web-site tell you one field at a
time what you have filled in wrong as you click Submit over and over and
over... *ESPECIALLY* if they don't pre-inform you of what is/isn't valid
input!
Sidebar:
If you're going to restrict what input is acceptable, inform the user in
fine print what's allowed! This includes claiming Zip+4 is invalid, you
goofs.
Sidebar:
For a username, could you at *LEAST* let me use my email for a username so
(A) it will be not "already used" and (B) I have a *CHANCE* of remembering
it when I come back?! I have to run through 20 different possiblities for
some sites I use semi-regularly when I log in. Other sites I never use
simply because I know I can't remember my username for that site.
Here's a slightly better design:
<?php
$message = '';
if (isset($submit)){ # The NAME= from your TYPE=SUBMIT button
if (!$Age){
$message .= "You must enter a valid age in years<BR>\n";
}
if (!$Email){
$message .= "You must enter a valid email<BR>\n";
}
}
if (!$message){
# Process valid input
}
else{
?>
<FORM ... >
<?php echo "<FONT COLOR=FF0000>$message</FONT>";?>
Age: <INPUT NAME=Age ...>
.
.
.
</FORM>
Sidebar:
You could go a lot further in validating the $Email. You could even type in
a three (3) page Regular Expression from the back of the Camel book and be
completely RFC-compliant... If you didn't mind the fact that it will
probably be dog-slow and very RAM-intensive. There are a bazillion
email-checking Regexes posted to the 'Net. Many of them will reject
perfectly valid emails :-( You need one that will maybe let a bad email
slip by, but will *NOT* reject any valid addresses. Good luck finding one.
No, I don't know where one is. You could also use some PHP functions
(SNMP?) to look up the MX record for the domain name of the email, and ask
that MX server if it accepts that email as valid... Only some MX servers
will just say "Yeah, sure" for invalid emails, and some will refuse to
answer at all, and some will just plain out-and-out lie and say an email is
invalid when it's fine. So, bottom line, if you *really* care about having
a valid email, you have to send a secret randomly-generated unique
registration code required to complete the registration to the address to
force the user to provide a working email. Of course, there's nothing to
stop them from creating a Yahoo (et al) email and checking it only once to
get the registration code, and never, ever, ever using that email address
again for anything. So, in the end, there's really not a whole lot of point
to doing all that, is there?... It boils down to: "How important is it to
you that they give you an email that might only be valid for a few hours?
Maybe you shouldn't require it at all." YMMV.
--
WARNING richard@zend.com address is an endangered species -- Use
ceo@l-i-e.com
Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm
Volunteer a little time: http://chatmusic.com/volunteer.htm