note 66788 added to tutorial.forms
| From: | Joe at osu1 dot php dot net | Date: | Mon, 29 May 2006 10:52:44 +0000 |
| Subject: | note 66788 added to tutorial.forms | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-112488@lists.php.net to get a copy of this message | ||
Just wanted to add a note:
For beginners, it is wise to use the "GET" method in forms because you can see what is
being sent between the server and the web browser.
For example, in the example above, if you change
<form action="action.php" method="post">
to <form action="action.php" method="get">
you would get something like...
http://www.myserver.com/action.php?name=A&age=B
in your web browser.
However, a good idea is to always change the "GET" to a "POST" because the user
of the browser cannot change the contents of the information being sent from the form to the
webserver.
In the example given above,
<form action="action.php" method="post">
Would just have,
http://www.myserver.com/action.php
As you can see, no information is visible to the user of the browser.
In other words, _GET and _POST, has a lot of advantage over one another. I personally use
"POST" in everything so that the user of the page cannot "spam" it by
continually sending information with GET.
Simply put, with "GET" the user can physically change the values that the server gets,
whereas with the "POST" method, the user will have a hard time changing the information
sent to the server.
For example, if you have a user login service, you definitely want to submit the form by a
"POST" so that if someone wants to "change" the account to something like admin,
then he would have a hard time doing so because he cannot directly change the information on the
browser URL line and then simply send it like that everytime.
----
Server IP: 66.163.161.117
Probable Submitter: 70.161.19.59
----
X-Spam-Status: No, hits=3.3 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER,
HTML_MESSAGE autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/tutorial.forms.php
Edit -- http://master.php.net/note/edit/66788
Del: integrated -- http://master.php.net/note/delete/66788/integrated
Del: useless -- http://master.php.net/note/delete/66788/useless
Del: bad code -- http://master.php.net/note/delete/66788/bad+code
Del: spam -- http://master.php.net/note/delete/66788/spam
Del: non-english -- http://master.php.net/note/delete/66788/non-english
Del: in docs -- http://master.php.net/note/delete/66788/in+docs
Del: other reasons-- http://master.php.net/note/delete/66788
Reject -- http://master.php.net/note/reject/66788
Search -- http://master.php.net/manage/user-notes.php