Re: creating edit form with QF. hidden field is not going through to process_data with other $values - ?
| From: | Justin Patrin | Date: | Tue, 21 Dec 2004 19:47:31 +0000 |
| Subject: | Re: creating edit form with QF. hidden field is not going through to process_data with other $values - ? | ||
| References: | 1 2 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-16381@lists.php.net to get a copy of this message | ||
On Tue, 21 Dec 2004 11:22:44 -0800 (PST), l Burnerheimerton
<lburnerheimerton@yahoo.com> wrote:
> Thanks for your ideas. I'll try the slashes idea bu tin the meantime, I did
> print_r($values) and POST and it was not in either one.
>
> If the slashes thing is wrong, it would never get to either one of those. I
> will try the stripslash and see if that works.
Well, if it's not even in $_POST then it's not being posted by the
browser. Look at your HTML again. Could you post the HTML here?
>
>
> Justin Patrin <papercrane@gmail.com> wrote:
>
> On Tue, 21 Dec 2004 02:43:48 -0800 (PST), l Burnerheimerton
> wrote:
> > I took the insert form and added defaults to the form fields and changed
> the SQL in the process_data function. I've worked with it changing many
> things and nothing seems to work.
> >
> > The problem is in the process_data function, the ID field is not getting
> through despite being a hidden field. I checked the souerce code of the foem
> before processing and it is a hidden field with the correct value.
> >
> > The form receives the initial id from a $_GET value. Then it calls itself
> in the process but the hidden field should go with it.
> >
> > Anyway, here's the code, any ideas are appreciated!
> >
> > $form = new HTML_QuickForm('newform');
> > if ($_POST['name'] == '') {
> > $g_ID = (get_magic_quotes_gpc()) ? $_GET['id'] :
> > addslashes($_GET['id']);
>
> This is not correct. If you use $g_ID in a form and it has "slashable"
> characters, the backslashes will get passed in. Always use the
> *correct* escaping method only when you need it.
>
> $g_ID = get_magic_quotes_gpc() ? stripslashes($_GET['id']) : $_GET['id'];
>
> > $res =& $db->query('SELECT f1, f2, f3, f4 FROM table WHERE
> r_ID='.$g_ID.'');
>
> Then here you should use $db->quoteSmart($g_ID);
>
> > $row =& $res->fetchRow();
> > }
> > $form->setDefaults(array(
> > 'Bg_ID' => $g_ID,
>
> This should stay as-is, QF will handle escaping for you.
>
> > 'name' => $row[0],
> > 'address' => $row[1],
> > 'city' => $row[2],
> > 'state' => $row[3]
> > )
> > );
> > $form->addElement('text', 'name', 'Name: ',
> > array('size'=>'50',
> 'maxlength'=>'50'));
> > $form->addElement('text', 'address', 'Addres: ',
> > array('size'=>'50',
> 'maxlength'=>'50'));
> > $form->addElement('text', 'city', 'City: ',
> > array('size'=>'25',
> 'maxlength'=>'25'));
> > $form->addElement('text', 'state', 'State: ',
> > array('size'=>'2',
> 'maxlength'=>'2'));
> > $form->addElement('hidden', 'bg_ID', $g_ID);
>
> ditto here
>
> > $form->addElement('submit', null, 'Update Fields');
> > if ($form->validate()) {
> > $form->process('process_data', false);
> > }
> > //INSERT data
> > function process_data ($values) {
>
> Try print_r($values) here. Is it in there?
>
> Try print_r($_POST); Is it in there?
>
> > $DDD_ID = $values['bg_ID'];
> > $arr = array($values['name'], $values['address'],
> > $values['city'],
> $values['state'],);
> > $resUPDATE = $db->prepare('UPDATE table SET f1=?, f2=?, f3=?, f4=? WHERE
> r_ID = '.$DDD_ID.'');
>
> Why are you setting $DDD_ID? Just use $valued['bg_ID']. You should
> also use quoteSmart() here.
>
> > $db->execute($resUPDATE, $arr);
> > if (DB::isError($resUPDATE)) {
> > die($resUPDATE->getMessage());
> > }
> > }
> > $form->display();
> >
>
> For more on magic quotes and escaping:
>
> http://www.reversefold.com/tikiwiki/tiki-index.php?page=PHPFAQs#id701117
>
> --
> Justin Patrin
>
--
Justin Patrin