Re: creating edit form with QF. hidden field is not going through to process_data with other $values - ?
| From: | Justin Patrin | Date: | Tue, 21 Dec 2004 17:48:05 +0000 |
| Subject: | Re: creating edit form with QF. hidden field is not going through to process_data with other $values - ? | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-16372@lists.php.net to get a copy of this message | ||
On Tue, 21 Dec 2004 02:43:48 -0800 (PST), l Burnerheimerton
<lburnerheimerton@yahoo.com> wrote:
> I took the insert form and added defaults to the form fields and changed the SQL in the
> process_data function. I've worked with it changing many things and nothing seems to work.
>
> The problem is in the process_data function, the ID field is not getting through despite being
> a hidden field. I checked the souerce code of the foem before processing and it is a hidden field
> with the correct value.
>
> The form receives the initial id from a $_GET value. Then it calls itself in the process but
> the hidden field should go with it.
>
> Anyway, here's the code, any ideas are appreciated!
>
> $form = new HTML_QuickForm('newform');
> if ($_POST['name'] == '') {
> $g_ID = (get_magic_quotes_gpc()) ? $_GET['id'] : addslashes($_GET['id']);
This is not correct. If you use $g_ID in a form and it has "slashable"
characters, the backslashes will get passed in. Always use the
*correct* escaping method only when you need it.
$g_ID = get_magic_quotes_gpc() ? stripslashes($_GET['id']) : $_GET['id'];
> $res =& $db->query('SELECT f1, f2, f3, f4 FROM table WHERE
> r_ID='.$g_ID.'');
Then here you should use $db->quoteSmart($g_ID);
> $row =& $res->fetchRow();
> }
> $form->setDefaults(array(
> 'Bg_ID' => $g_ID,
This should stay as-is, QF will handle escaping for you.
> 'name' => $row[0],
> 'address' => $row[1],
> 'city' => $row[2],
> 'state' => $row[3]
> )
> );
> $form->addElement('text', 'name', 'Name: ',
> array('size'=>'50', 'maxlength'=>'50'));
> $form->addElement('text', 'address', 'Addres: ',
> array('size'=>'50', 'maxlength'=>'50'));
> $form->addElement('text', 'city', 'City: ',
> array('size'=>'25', 'maxlength'=>'25'));
> $form->addElement('text', 'state', 'State: ',
> array('size'=>'2', 'maxlength'=>'2'));
> $form->addElement('hidden', 'bg_ID', $g_ID);
ditto here
> $form->addElement('submit', null, 'Update Fields');
> if ($form->validate()) {
> $form->process('process_data', false);
> }
> //INSERT data
> function process_data ($values) {
Try print_r($values) here. Is it in there?
Try print_r($_POST); Is it in there?
> $DDD_ID = $values['bg_ID'];
> $arr = array($values['name'], $values['address'],
> $values['city'], $values['state'],);
> $resUPDATE = $db->prepare('UPDATE table SET f1=?, f2=?, f3=?, f4=? WHERE r_ID =
> '.$DDD_ID.'');
Why are you setting $DDD_ID? Just use $valued['bg_ID']. You should
also use quoteSmart() here.
> $db->execute($resUPDATE, $arr);
> if (DB::isError($resUPDATE)) {
> die($resUPDATE->getMessage());
> }
> }
> $form->display();
>
For more on magic quotes and escaping:
http://www.reversefold.com/tikiwiki/tiki-index.php?page=PHPFAQs#id701117
--
Justin Patrin