note 37220 added to language.variables.external
| From: | php-general at lists dot php dot net | Date: | Fri, 07 Nov 2003 02:07:33 +0000 |
| Subject: | note 37220 added to language.variables.external | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-60036@lists.php.net to get a copy of this message | ||
It's been driving me mad, but I've finally worked out the only way to reliably allow form
data to be fed back into a form (for editing a record, for instance) is like this:
echo "<input type='text' name='varname' ";
if(isset($existingvalue))
echo "value=\"".htmlspecialchars(stripslashes($existingvalue))."\"
";
echo "/>";
This assumes that variables have been escaped (such as addslashes) after being retrieved from the
database or after being received from a (probably this) form.
Note the type of quotes used in the code above: the value attribute must use escaped double-quotes,
and the echo command must use double-quotes, or errors occur when single quotes appear in the data.
htmlspecialchars will protect the form from errors caused by data that contains double quote marks,
and it stops errors occurring when triangle brackets < > are present in the data.
Alas, to make your site display properly, you must also use htmlspecialchars every time string data
is displayed to the user.
There might be an easier way of allowing data to safely be put back into a form, but if there is,
I've spent a lot of time not finding it.
----
Manual Page -- http://www.php.net/manual/en/language.variables.external.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+37220
Delete -- http://master.php.net/manage/user-notes.php?action=delete+37220&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+37220&report=yes
Search -- http://master.php.net/manage/user-notes.php