Re: RFC: PECL validation extension
| From: | Xavier Noguer | Date: | Thu, 18 Sep 2003 09:18:31 +0000 |
| Subject: | Re: RFC: PECL validation extension | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-21695@lists.php.net to get a copy of this message | ||
Alan Knowles <alan@akbkhome.com> escribió
> I came up with something very similar in PHP...
> Gtk_ValidateManager
>
>
> Same principle - have xml (wddx in my case), store a map of
> a) what items where expected from a form (obtained by using the HTML
> Parser in Flexy),
> b) against a test (a method in a user defined class) which return
true/false
> c) Message (The Incorrect value message)..
>
> Since editing the xml/wddx file was a royal pain in the backside.. - I
> ended up doing a Gtk Interface to modify both the xml/wddx file and the
> class it'self..
>
> The base class for validation
>
>
http://devel.akbkhome.com/svn/index.php/akpear/Gtk_ValidateManager/ValidateManager/Base.php
>
> A Projects Validation rules
>
> http://devel.akbkhome.com/svn/index.php/hebehaven2/ValidateHebe.php.wddx
> (and the very messy code that is generated from it..)
>
> http://devel.akbkhome.com/svn/index.php/hebehaven2/ValidateHebe.php
>
> A typical rule file for a html page.
>
http://devel.akbkhome.com/svn/index.php/hebehaven2/templates/backend/members_edit.html.rules.wddx
>
>
> Theres a few ideas to borrow if you like..
Having to work with wddx seems a bit cumbersome, especially having the
validating code as part of it. But I really liked the idea of customizing
error messages, since probably the default ones will not be very useful most
of the time.
> - I'm not sure how much it benifets from being done in C though..
At first I did it in php too :). The benefit for doing it in C is mostly just
performance. I just wanted to have a taste of how difficult it would be to
port my previous code to C and ended up doing almost the whole thing (the php
version included an autentication/authorization part, that's what the modules
in the config file are for).
> >
> > What I haven't decided on yet is the following:
> > - Is there any sense in having an auto_validate option that silently
> > validates, or is this prone to cause more problems than it would solve?
>
> Try and avoid too much magic... - I'm sure you have spent as much of
> your life pooring oversomeones code for hours just cause they used one
> of these hidden tricks.
> $errors = validate($rule_file);
> would seem more logical.. - follow the flow of the program...
The more I think about it, the worst it seems the silent validation option.. I
think for now I'll stick to explicit validation.
> > - Should all parameters declare their method (post or get)?
> optionally.. I guess.. - default = none = $_request..
>
>
> > - Currently, parameters that are received that were not declared simply
> > ignored. I think I should force all parameters to be declared, and
receiving
> > an undeclared parameter should cause an error.
>
> a strict flag on the page...
I had thought about an application-wide flag, but per-file/per-app seems more
flexible.
Thanks for the feedback.
Xavier
http://www.xavier-noguer.com/