note 39880 deleted from function.trim by tomsommer
| From: | tomsommer@php.net | Date: | Fri, 13 Feb 2004 22:44:15 +0000 |
| Subject: | note 39880 deleted from function.trim by tomsommer | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-65121@lists.php.net to get a copy of this message | ||
Note Submitter: sean@inexo.com
----
Having whitespace in incoming form data can be dangerous or can potentially break your script.
(imagine if we could allow the usernames 'bob', 'bob ', and 'bob '!)
I have a quick and dirty solution to the whitespace problem.
function postCleaner($post)
{ while (list($key, $val) = each($post))
{ if (is_string($post[$key]))
{ $post[$key] = trim($val);
} elseif (is_array($post[$key]))
{ $post[$key] = postCleaner($post[$key]);
}
}
return $post;
}
Use this in your form processing script like so...
<?
if ($_POST["update_submit"] == "Submit")
{ $formPost = postCleaner($_POST);
//formPost is now free of whitespace
}
?>
This builds on an earlier comment but I think it is somewhat cleaner and easier to implement