Re: creating edit form with QF. hidden field is not going through to process_data with other $values - ?

From: Date: Tue, 21 Dec 2004 19:22:44 +0000
Subject: Re: creating edit form with QF. hidden field is not going through to process_data with other $values - ?
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-16378@lists.php.net to get a copy of this message
Thanks for your ideas. I'll try the slashes idea bu tin the meantime, I did print_r($values) and POST and it was not in either one. If the slashes thing is wrong, it would never get to either one of those. I will try the stripslash and see if that works. Justin Patrin <papercrane@gmail.com> wrote: On Tue, 21 Dec 2004 02:43:48 -0800 (PST), l Burnerheimerton wrote: > I took the insert form and added defaults to the form fields and changed the SQL in the > process_data function. I've worked with it changing many things and nothing seems to work. > > The problem is in the process_data function, the ID field is not getting through despite being > a hidden field. I checked the souerce code of the foem before processing and it is a hidden field > with the correct value. > > The form receives the initial id from a $_GET value. Then it calls itself in the process but > the hidden field should go with it. > > Anyway, here's the code, any ideas are appreciated! > > $form = new HTML_QuickForm('newform'); > if ($_POST['name'] == '') { > $g_ID = (get_magic_quotes_gpc()) ? $_GET['id'] : addslashes($_GET['id']); This is not correct. If you use $g_ID in a form and it has "slashable" characters, the backslashes will get passed in. Always use the *correct* escaping method only when you need it. $g_ID = get_magic_quotes_gpc() ? stripslashes($_GET['id']) : $_GET['id']; > $res =& $db->query('SELECT f1, f2, f3, f4 FROM table WHERE > r_ID='.$g_ID.''); Then here you should use $db->quoteSmart($g_ID); > $row =& $res->fetchRow(); > } > $form->setDefaults(array( > 'Bg_ID' => $g_ID, This should stay as-is, QF will handle escaping for you. > 'name' => $row[0], > 'address' => $row[1], > 'city' => $row[2], > 'state' => $row[3] > ) > ); > $form->addElement('text', 'name', 'Name: ', > array('size'=>'50', 'maxlength'=>'50')); > $form->addElement('text', 'address', 'Addres: ', > array('size'=>'50', 'maxlength'=>'50')); > $form->addElement('text', 'city', 'City: ', > array('size'=>'25', 'maxlength'=>'25')); > $form->addElement('text', 'state', 'State: ', > array('size'=>'2', 'maxlength'=>'2')); > $form->addElement('hidden', 'bg_ID', $g_ID); ditto here > $form->addElement('submit', null, 'Update Fields'); > if ($form->validate()) { > $form->process('process_data', false); > } > //INSERT data > function process_data ($values) { Try print_r($values) here. Is it in there? Try print_r($_POST); Is it in there? > $DDD_ID = $values['bg_ID']; > $arr = array($values['name'], $values['address'], > $values['city'], $values['state'],); > $resUPDATE = $db->prepare('UPDATE table SET f1=?, f2=?, f3=?, f4=? WHERE r_ID = > '.$DDD_ID.''); Why are you setting $DDD_ID? Just use $valued['bg_ID']. You should also use quoteSmart() here. > $db->execute($resUPDATE, $arr); > if (DB::isError($resUPDATE)) { > die($resUPDATE->getMessage()); > } > } > $form->display(); > For more on magic quotes and escaping: http://www.reversefold.com/tikiwiki/tiki-index.php?page=PHPFAQs#id701117 -- Justin Patrin __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com

« previous php.pear.general (#16378) next »