note 44534 deleted from function.eregi by tomsommer

From: Date: Mon, 09 Aug 2004 12:16:12 +0000
Subject: note 44534 deleted from function.eregi by tomsommer
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-74316@lists.php.net to get a copy of this message
Note Submitter: forestgump_777@yahoo.com ---- Here is a exemple of a code (with eregi) I use to protect my Login/Password identification script, against a apostrophe ('). The script receive the variable "Login" and "Passport" from a html post. The problem is.. if "Login" & "Passport" contain a apostrophe this will cause an error in the mysql synthax. With my code,you can execute the function CheckCharactere and it will tell you, by a Javascript Alert not to use the apostrophe if he find one and it will stop the identification script. The use of eregi is essential. $endroit[1] = $_POST['Login']; // The array must be defined here before. $endroit[2] = $_POST['Passport']; if (CheckCharactere($ChoixAffichage="Java",$endroit) == TRUE) { /* many functions here...continue the identification script..because everything if fine. There's no apostrophe found.*/ } function CheckCharactere($ChoixAffichage, $endroit) { /* This function can be put in a file like, protection.php */ $i = 1; $max = count ($endroit) +1; print($max); while ($i < $max) { if (eregi("'", $endroit[$i])) { $reponse = "Avertissement: A cause d'une imcompatibilite technique,\ l'utilisation de l'apostrophe est interdit à cet endroit du site, vous \ pourrez toutefois l'utiliser dans votre description de profil. Because of a\ technical incompatibility, you cannot use a apostrophe"; if ($ChoixAffichage == "Java") { echo "<SCRIPT LANGUAGE=\"JavaScript\"> alert(\"$reponse\") </script>"; $i = $max; } else { print($reponse); $i++; }} else { $i++; if ($i == $max) { return TRUE; } } } } Simple, if he find a apostrophe, he can show a alert in Java or direct in the Html result with the buffer in $reponse. But if you have to use absolutely the apostrophe you can choose the eregi_replace function to change the apostrophe "'" with (apostrophe), as example. So the text: Here is a Apostrophe '. will be changed to: Here is a Apostrophe (apostrophe). You can store this text in your mysql database, without problem, because you have no more apostrophe in the syntax. After you call the function eregi_replace to change back (apostrophe) to ' when you need the text. I Hope this help, sorry for my english Im a french Canadian.

« previous php.notes (#74316) next »