Re: [QuickForm] How should i use applyFilter()

From: Date: Thu, 30 May 2002 11:31:01 +0000
Subject: Re: [QuickForm] How should i use applyFilter()
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-1517@lists.php.net to get a copy of this message
Bertrand Mansion wrote: >This is true. My mistake, I took a shortcut. >I usually override the process() method to get submitted values. To do that, >I use this code : > >function process() { > $values = $this-> submitValues; > while(list($k, $v) = each($values)) { > if (is string($val)) > $val = addslashes($val); > $cleanValues[$key] = $val; > } > return $cleanValues; >} Oh, yes. Making class that extends QuickForm is a solution, but I don't like to have classes that I use only in one place. Maybe I'm freak. ;) >Using or not magic quotes gpc is user's choice so we won't deal with this >issue. submitValues contains the submitted values after they have been >filtered. getElementValue returns the value of the element as it was >submitted by the form before being filtered. I think this distinction can be >useful. So I would consider keeping it if you don't mind. OK, i agree with that. I think it would be great to have filter 'stripslashes' because in my case (and possibly many others) using magic_quotes_gpc is host's choice not my. So I could use: $form->applyFilter('__ALL__', 'stripslashes'); Instead of manualy stripping. >But I think we miss a method to access the submitted and filtered values. >What do you think of a getSubmitValue($elementName) method ? Or maybe just >add a parameter to getElementValue to say if we want the value before or >after it has been filtered, with default being after ? >Option 2 is better IMO. Great idea. Why not both? I think there's also an issue with slashes, see the code: ----------------------------------------------------------- require_once 'HTML/QuickForm.php'; $form = new HTML_QuickForm(); $form->setDefaults(array( 'test' => 'Default\\\\test"foo\'bla\\gre' )); // test should be: Default\\test"foo'bla\gre $form->addElement('text', 'test'); // test is: Default\test"foo'blagre (missing backslashes) // just to make validate() work: $form->addRule('test', null, 'required'); if ($form->validate()) { echo 'magic_quotes_gpc = ' . (get_magic_quotes_gpc()?'on':'off') . '<br>'; echo "_submitValues['test'] = " . $form->_submitValues['test'] . '<br>'; echo "getElementValue('test') = " . $form->getElementValue('test') . '<br>'; } $form->display(); ---------------------------------------------------------- Shouldn't be following line in setDefaults removed? $value = is_string($value) ? stripslashes($value) : $value; Now using this code i type into input box: Input\\test"foo'bla\gre Depending on magic_quotes_gpc setting i get: magic_quotes_gpc = on _submitValues['test'] = Input\\\\test\"foo\'bla\\gre getElementValue('test') = Input\\test"foo'bla\gre This is ok, and after changing settings i get: magic_quotes_gpc = off _submitValues['test'] = Input\\test"foo'bla\gre getElementValue('test') = Input\test"foo'blagre This isn't ok (missing backslashes). The former one is also displayed in input box. I don't know where it is in code, but it should check get_magic_quotes_gpc() before stripping. >Thanks for your feedback, I'm only trying to fit QuickForm to my needs. :) BTW, is my english very bad? I wonder how can you understand me. :) - Wojtek

« previous php.pear.general (#1517) next »