note 39880 added to function.trim
| From: | sean at inexo dot com | Date: | Fri, 13 Feb 2004 21:18:48 +0000 |
| Subject: | note 39880 added to function.trim | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-65118@lists.php.net to get a copy of this message | ||
Having whitespace in incoming form data can be dangerous or can potentially break your script.
(imagine if we could allow the usernames 'bob', 'bob ', and 'bob '!)
I have a quick and dirty solution to the whitespace problem.
function postCleaner($post)
{ while (list($key, $val) = each($post))
{ if (is_string($post[$key]))
{ $post[$key] = trim($val);
} elseif (is_array($post[$key]))
{ $post[$key] = postCleaner($post[$key]);
}
}
return $post;
}
Use this in your form processing script like so...
<?
if ($_POST["update_submit"] == "Submit")
{ $formPost = postCleaner($_POST);
//formPost is now free of whitespace
}
?>
This builds on an earlier comment but I think it is somewhat cleaner and easier to implement
----
Manual Page -- http://www.php.net/manual/en/function.trim.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+39880
Delete -- http://master.php.net/manage/user-notes.php?action=delete+39880&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+39880&report=yes
Search -- http://master.php.net/manage/user-notes.php