Re: [QuickForm] How should i use applyFilter()
| From: | Wojciech Gdela | Date: | Thu, 30 May 2002 11:31:01 +0000 |
| Subject: | Re: [QuickForm] How should i use applyFilter() | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-1517@lists.php.net to get a copy of this message | ||
Bertrand Mansion wrote:
>This is true. My mistake, I took a shortcut.
>I usually override the process() method to get submitted values. To do that,
>I use this code :
>
>function process() {
> $values = $this-> submitValues;
> while(list($k, $v) = each($values)) {
> if (is string($val))
> $val = addslashes($val);
> $cleanValues[$key] = $val;
> }
> return $cleanValues;
>}
Oh, yes. Making class that extends QuickForm is a solution, but I
don't like to have classes that I use only in one place. Maybe I'm
freak. ;)
>Using or not magic quotes gpc is user's choice so we won't deal with this
>issue. submitValues contains the submitted values after they have been
>filtered. getElementValue returns the value of the element as it was
>submitted by the form before being filtered. I think this distinction can be
>useful. So I would consider keeping it if you don't mind.
OK, i agree with that. I think it would be great to have filter
'stripslashes' because in my case (and possibly many others) using
magic_quotes_gpc is host's choice not my. So I could use:
$form->applyFilter('__ALL__', 'stripslashes');
Instead of manualy stripping.
>But I think we miss a method to access the submitted and filtered values.
>What do you think of a getSubmitValue($elementName) method ? Or maybe just
>add a parameter to getElementValue to say if we want the value before or
>after it has been filtered, with default being after ?
>Option 2 is better IMO.
Great idea. Why not both?
I think there's also an issue with slashes, see the code:
-----------------------------------------------------------
require_once 'HTML/QuickForm.php';
$form = new HTML_QuickForm();
$form->setDefaults(array(
'test' => 'Default\\\\test"foo\'bla\\gre'
));
// test should be: Default\\test"foo'bla\gre
$form->addElement('text', 'test');
// test is: Default\test"foo'blagre (missing backslashes)
// just to make validate() work:
$form->addRule('test', null, 'required');
if ($form->validate()) {
echo 'magic_quotes_gpc = '
. (get_magic_quotes_gpc()?'on':'off')
. '<br>';
echo "_submitValues['test'] = "
. $form->_submitValues['test']
. '<br>';
echo "getElementValue('test') = "
. $form->getElementValue('test')
. '<br>';
}
$form->display();
----------------------------------------------------------
Shouldn't be following line in setDefaults removed?
$value = is_string($value) ? stripslashes($value) : $value;
Now using this code i type into input box: Input\\test"foo'bla\gre
Depending on magic_quotes_gpc setting i get:
magic_quotes_gpc = on
_submitValues['test'] = Input\\\\test\"foo\'bla\\gre
getElementValue('test') = Input\\test"foo'bla\gre
This is ok, and after changing settings i get:
magic_quotes_gpc = off
_submitValues['test'] = Input\\test"foo'bla\gre
getElementValue('test') = Input\test"foo'blagre
This isn't ok (missing backslashes). The former one is also displayed
in input box. I don't know where it is in code, but it should check
get_magic_quotes_gpc() before stripping.
>Thanks for your feedback,
I'm only trying to fit QuickForm to my needs. :)
BTW, is my english very bad? I wonder how can you understand me. :)
- Wojtek