note 53377 deleted from function.ereg by nlopess
| From: | nlopess@php.net | Date: | Wed, 13 Jul 2005 12:52:38 +0000 |
| Subject: | note 53377 deleted from function.ereg by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-91891@lists.php.net to get a copy of this message | ||
Note Submitter: php at easy2sync dot com
----
When working with variables from web forms you should
never assume that their content is what it's supposed to be.Especially if these strings get
into a database command
string. Ereg makes it easy to check it:
Checking for a legal e-mail:
function IsEMail ($string)
{
if (ereg("^[A-Za-z0-9_\.\-]+@[A-Za-z0-9_\.\-]"+
"+\.[A-Za-z0-9_\-][A-Za-z0-9_\-]+$", $string, $result))
return (true);
return (false);
}
Making the string safe to process as e-mail. Removes spaces, newlines, quotation marks, etc.:
function MakeSafe ($string)
{
$string = preg_replace("/[^a-zA-Z0-9\-\.\@\_]/", "", $string);
return ($string);
}
Thomas
--------------------------------------------
http://www.easy2sync.com/en/produkte/e2s4o.php