Re: creating edit form with QF. hidden field is not going through to process_data with other $values - ?

From: Date: Tue, 21 Dec 2004 19:47:31 +0000
Subject: Re: creating edit form with QF. hidden field is not going through to process_data with other $values - ?
References: 1 2  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-16381@lists.php.net to get a copy of this message
On Tue, 21 Dec 2004 11:22:44 -0800 (PST), l Burnerheimerton <lburnerheimerton@yahoo.com> wrote: > Thanks for your ideas. I'll try the slashes idea bu tin the meantime, I did > print_r($values) and POST and it was not in either one. > > If the slashes thing is wrong, it would never get to either one of those. I > will try the stripslash and see if that works. Well, if it's not even in $_POST then it's not being posted by the browser. Look at your HTML again. Could you post the HTML here? > > > Justin Patrin <papercrane@gmail.com> wrote: > > On Tue, 21 Dec 2004 02:43:48 -0800 (PST), l Burnerheimerton > wrote: > > I took the insert form and added defaults to the form fields and changed > the SQL in the process_data function. I've worked with it changing many > things and nothing seems to work. > > > > The problem is in the process_data function, the ID field is not getting > through despite being a hidden field. I checked the souerce code of the foem > before processing and it is a hidden field with the correct value. > > > > The form receives the initial id from a $_GET value. Then it calls itself > in the process but the hidden field should go with it. > > > > Anyway, here's the code, any ideas are appreciated! > > > > $form = new HTML_QuickForm('newform'); > > if ($_POST['name'] == '') { > > $g_ID = (get_magic_quotes_gpc()) ? $_GET['id'] : > > addslashes($_GET['id']); > > This is not correct. If you use $g_ID in a form and it has "slashable" > characters, the backslashes will get passed in. Always use the > *correct* escaping method only when you need it. > > $g_ID = get_magic_quotes_gpc() ? stripslashes($_GET['id']) : $_GET['id']; > > > $res =& $db->query('SELECT f1, f2, f3, f4 FROM table WHERE > r_ID='.$g_ID.''); > > Then here you should use $db->quoteSmart($g_ID); > > > $row =& $res->fetchRow(); > > } > > $form->setDefaults(array( > > 'Bg_ID' => $g_ID, > > This should stay as-is, QF will handle escaping for you. > > > 'name' => $row[0], > > 'address' => $row[1], > > 'city' => $row[2], > > 'state' => $row[3] > > ) > > ); > > $form->addElement('text', 'name', 'Name: ', > > array('size'=>'50', > 'maxlength'=>'50')); > > $form->addElement('text', 'address', 'Addres: ', > > array('size'=>'50', > 'maxlength'=>'50')); > > $form->addElement('text', 'city', 'City: ', > > array('size'=>'25', > 'maxlength'=>'25')); > > $form->addElement('text', 'state', 'State: ', > > array('size'=>'2', > 'maxlength'=>'2')); > > $form->addElement('hidden', 'bg_ID', $g_ID); > > ditto here > > > $form->addElement('submit', null, 'Update Fields'); > > if ($form->validate()) { > > $form->process('process_data', false); > > } > > //INSERT data > > function process_data ($values) { > > Try print_r($values) here. Is it in there? > > Try print_r($_POST); Is it in there? > > > $DDD_ID = $values['bg_ID']; > > $arr = array($values['name'], $values['address'], > > $values['city'], > $values['state'],); > > $resUPDATE = $db->prepare('UPDATE table SET f1=?, f2=?, f3=?, f4=? WHERE > r_ID = '.$DDD_ID.''); > > Why are you setting $DDD_ID? Just use $valued['bg_ID']. You should > also use quoteSmart() here. > > > $db->execute($resUPDATE, $arr); > > if (DB::isError($resUPDATE)) { > > die($resUPDATE->getMessage()); > > } > > } > > $form->display(); > > > > For more on magic quotes and escaping: > > http://www.reversefold.com/tikiwiki/tiki-index.php?page=PHPFAQs#id701117 > > -- > Justin Patrin > -- Justin Patrin

« previous php.pear.general (#16381) next »