note 37220 deleted from language.variables.external by danbrown

From: Date: Wed, 09 Mar 2011 14:42:05 +0000
Subject: note 37220 deleted from language.variables.external by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-177710@lists.php.net to get a copy of this message
Note Submitter: ---- It's been driving me mad, but I've finally worked out the only way to reliably allow form data to be fed back into a form (for editing a record, for instance) is like this: echo "<input type='text' name='varname' "; if(isset($existingvalue)) echo "value=\"".htmlspecialchars(stripslashes($existingvalue))."\" "; echo "/>"; This assumes that variables have been escaped (such as addslashes) after being retrieved from the database or after being received from a (probably this) form. Note the type of quotes used in the code above: the value attribute must use escaped double-quotes, and the echo command must use double-quotes, or errors occur when single quotes appear in the data. htmlspecialchars will protect the form from errors caused by data that contains double quote marks, and it stops errors occurring when triangle brackets < > are present in the data. Alas, to make your site display properly, you must also use htmlspecialchars every time string data is displayed to the user. There might be an easier way of allowing data to safely be put back into a form, but if there is, I've spent a lot of time not finding it.

« previous php.notes (#177710) next »