Re: [QUICKFORM] Freeze

From: Date: Sat, 01 Apr 2006 00:09:11 +0000
Subject: Re: [QUICKFORM] Freeze
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-23498@lists.php.net to get a copy of this message
On 5/20/05, Obsessed <Obsessed@dayofdefeat.be> wrote: > > I'm creating a page that let people make newsposts. > After the first submit I want them to get a page with a preview of their > submitted item, and then they can submit it or go back and alter it. > > I'm displaying the preview by using freeze() on my form. > This works very nicely but I only have on problem. > If users used html in their post to give it some layout, I'm getting > those tags in the preview as text instead of them 'working' if you know > what I mean. > > Is there any way to display correct html in form elements while in > frozen state? Nearly a year after the fact, but I've just been trying to solve this problem, and as this was the only reference to someone thinking about it too, I thought I'd post my solution in the hope it'll help someone else in the future. I wanted to let users entering text in a textarea to be able to use some HTML tags and have them appear correctly when previewing, when the form is frozen. I created a new HTML_Quickform element class, as shown below. This simply overrides the standard textarea element's getFrozenHtml() method - the only difference being that htmlspecialchars() isn't applied to the text: // START require_once("HTML/QuickForm/textarea.php"); class HTML_QuickForm_textareahtml extends HTML_QuickForm_textarea { function getFrozenHtml() { $value = $this->getValue(); if ($this->getAttribute('wrap') == 'off') { $html = $this->_getTabs() . '<pre>' . $value."</pre>\n"; } else { $html = nl2br($value)."\n"; } return $html . $this->_getPersistantData(); } } // END I saved this file as textareahtml.php with my other include files. Then in my form page I added this line: $GLOBALS['HTML_QUICKFORM_ELEMENT_TYPES']['textareahtml'] = array('path/to/file/textareahtml.php', 'HTML_QuickForm_textareahtml'); I could then create the element like this: $form->addElement('textareahtml', 'variablename'); When you freeze the form and render it, the user's HTML should be displayed correctly. However, you should be careful about user input, as they could severely mess up the page with broken HTML and more malicious things. So do this: $form->applyFilter('variablename', 'yourFilterMethod'); And have yourFilterMethod() make sure the HTML is good. I've used http://code.iamcal.com/php/lib_filter/lib_filter.phps to balance tags and only allow certain HTML tags through. Hope that helps someone, Phil

« previous php.pear.general (#23498) next »