note 37220 added to language.variables.external

From: Date: Fri, 07 Nov 2003 02:07:33 +0000
Subject: note 37220 added to language.variables.external
Groups: php.notes 
Request: Send a blank email to php-notes+get-60036@lists.php.net to get a copy of this message
It's been driving me mad, but I've finally worked out the only way to reliably allow form data to be fed back into a form (for editing a record, for instance) is like this: echo "<input type='text' name='varname' "; if(isset($existingvalue)) echo "value=\"".htmlspecialchars(stripslashes($existingvalue))."\" "; echo "/>"; This assumes that variables have been escaped (such as addslashes) after being retrieved from the database or after being received from a (probably this) form. Note the type of quotes used in the code above: the value attribute must use escaped double-quotes, and the echo command must use double-quotes, or errors occur when single quotes appear in the data. htmlspecialchars will protect the form from errors caused by data that contains double quote marks, and it stops errors occurring when triangle brackets < > are present in the data. Alas, to make your site display properly, you must also use htmlspecialchars every time string data is displayed to the user. There might be an easier way of allowing data to safely be put back into a form, but if there is, I've spent a lot of time not finding it. ---- Manual Page -- http://www.php.net/manual/en/language.variables.external.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+37220 Delete -- http://master.php.net/manage/user-notes.php?action=delete+37220&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+37220&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#60036) next »