note 39880 added to function.trim

From: Date: Fri, 13 Feb 2004 21:18:48 +0000
Subject: note 39880 added to function.trim
Groups: php.notes 
Request: Send a blank email to php-notes+get-65118@lists.php.net to get a copy of this message
Having whitespace in incoming form data can be dangerous or can potentially break your script. (imagine if we could allow the usernames 'bob', 'bob ', and 'bob '!) I have a quick and dirty solution to the whitespace problem. function postCleaner($post) { while (list($key, $val) = each($post)) { if (is_string($post[$key])) { $post[$key] = trim($val); } elseif (is_array($post[$key])) { $post[$key] = postCleaner($post[$key]); } } return $post; } Use this in your form processing script like so... <? if ($_POST["update_submit"] == "Submit") { $formPost = postCleaner($_POST); //formPost is now free of whitespace } ?> This builds on an earlier comment but I think it is somewhat cleaner and easier to implement ---- Manual Page -- http://www.php.net/manual/en/function.trim.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+39880 Delete -- http://master.php.net/manage/user-notes.php?action=delete+39880&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+39880&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#65118) next »