Re: PHP_SELF
| From: | Chris Worth | Date: | Fri, 03 Aug 2001 14:23:54 +0000 |
| Subject: | Re: PHP_SELF | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-61129@lists.php.net to get a copy of this message | ||
You make some good points richard,
I like the email as username, for just the reasons you mention :)
On Fri, 3 Aug 2001 00:42:30 -0500, Richard Lynch wrote:
>> if(!$Age) { echo "Please enter your age"; }
>> elseif(!$Email){ echo "Please enter your email"; }
>> else
>> echo "Thanks for your submission";
>> // continue processing...
>> }
>
>*ACTUALLY*, it's rather annoying to have a web-site tell you one field at a
>time what you have filled in wrong as you click Submit over and over and
>over... *ESPECIALLY* if they don't pre-inform you of what is/isn't valid
>input!
>
>Sidebar:
>If you're going to restrict what input is acceptable, inform the user in
>fine print what's allowed! This includes claiming Zip+4 is invalid, you
>goofs.
>
>Sidebar:
>For a username, could you at *LEAST* let me use my email for a username so
>(A) it will be not "already used" and (B) I have a *CHANCE* of remembering
>it when I come back?! I have to run through 20 different possiblities for
>some sites I use semi-regularly when I log in. Other sites I never use
>simply because I know I can't remember my username for that site.
>
>Here's a slightly better design:
>
><?php
> $message = '';
> if (isset($submit)){ # The NAME= from your TYPE=SUBMIT button
> if (!$Age){
> $message .= "You must enter a valid age in years<BR>\n";
> }
> if (!$Email){
> $message .= "You must enter a valid email<BR>\n";
> }
> }
> if (!$message){
> # Process valid input
> }
> else{
>?>
><FORM ... >
> <?php echo "<FONT COLOR=FF0000>$message</FONT>";?>
> Age: <INPUT NAME=Age ...>
>.
>.
>.
></FORM>
>
>Sidebar:
>You could go a lot further in validating the $Email. You could even type in
>a three (3) page Regular Expression from the back of the Camel book and be
>completely RFC-compliant... If you didn't mind the fact that it will
>probably be dog-slow and very RAM-intensive. There are a bazillion
>email-checking Regexes posted to the 'Net. Many of them will reject
>perfectly valid emails :-( You need one that will maybe let a bad email
>slip by, but will *NOT* reject any valid addresses. Good luck finding one.
>No, I don't know where one is. You could also use some PHP functions
>(SNMP?) to look up the MX record for the domain name of the email, and ask
>that MX server if it accepts that email as valid... Only some MX servers
>will just say "Yeah, sure" for invalid emails, and some will refuse to
>answer at all, and some will just plain out-and-out lie and say an email is
>invalid when it's fine. So, bottom line, if you *really* care about having
>a valid email, you have to send a secret randomly-generated unique
>registration code required to complete the registration to the address to
>force the user to provide a working email. Of course, there's nothing to
>stop them from creating a Yahoo (et al) email and checking it only once to
>get the registration code, and never, ever, ever using that email address
>again for anything. So, in the end, there's really not a whole lot of point
>to doing all that, is there?... It boils down to: "How important is it to
>you that they give you an email that might only be valid for a few hours?
>Maybe you shouldn't require it at all." YMMV.
>
>--
>WARNING richard@zend.com address is an endangered species -- Use
>ceo@l-i-e.com
>Wanna help me out? Like Music? Buy a CD:
>http://l-i-e.com/artists.htm
>Volunteer a little time: http://chatmusic.com/volunteer.htm
>
>
>
>--
>PHP General Mailing List (http://www.php.net/)
>To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
>For additional commands, e-mail: php-general-help@lists.php.net
>To contact the list administrators, e-mail: php-list-admin@lists.php.net
>