note 44534 deleted from function.eregi by tomsommer
| From: | tomsommer@php.net | Date: | Mon, 09 Aug 2004 12:16:12 +0000 |
| Subject: | note 44534 deleted from function.eregi by tomsommer | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-74316@lists.php.net to get a copy of this message | ||
Note Submitter: forestgump_777@yahoo.com
----
Here is a exemple of a code (with eregi) I use to protect my Login/Password identification script,
against a apostrophe (').
The script receive the variable "Login" and "Passport" from a html post. The
problem is.. if "Login" & "Passport" contain a apostrophe this will cause an
error in the mysql synthax. With my code,you can execute the function CheckCharactere and it will
tell you, by a Javascript Alert not to use the apostrophe if he find one and it will stop the
identification script. The use of eregi is essential.
$endroit[1] = $_POST['Login']; // The array must be defined here before.
$endroit[2] = $_POST['Passport'];
if (CheckCharactere($ChoixAffichage="Java",$endroit) == TRUE) {
/* many functions here...continue the identification script..because everything if fine.
There's no apostrophe found.*/ }
function CheckCharactere($ChoixAffichage, $endroit)
{
/* This function can be put in a file like, protection.php */
$i = 1;
$max = count ($endroit) +1;
print($max);
while ($i < $max) {
if (eregi("'", $endroit[$i])) {
$reponse = "Avertissement: A cause d'une imcompatibilite technique,\
l'utilisation de l'apostrophe est interdit à cet endroit du site, vous \
pourrez toutefois l'utiliser dans votre description de profil. Because of a\
technical incompatibility, you cannot use a apostrophe";
if ($ChoixAffichage == "Java") {
echo "<SCRIPT LANGUAGE=\"JavaScript\">
alert(\"$reponse\")
</script>"; $i = $max; }
else { print($reponse); $i++; }}
else { $i++; if ($i == $max) { return TRUE; } }
}
}
Simple, if he find a apostrophe, he can show a alert in Java or direct in the Html result with the
buffer in $reponse. But if you have to use absolutely the apostrophe you can choose the
eregi_replace function to change the apostrophe "'" with (apostrophe), as example. So
the text: Here is a Apostrophe '. will be changed to: Here is a Apostrophe (apostrophe).
You can store this text in your mysql database, without problem, because you have no more apostrophe
in the syntax. After you call the function eregi_replace to change back (apostrophe) to ' when
you need the text.
I Hope this help, sorry for my english Im a french Canadian.