Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #17905

Re: Question on form validation

Message-ID <2054338.ZTifN9JQ4c@PointedEars.de> (permalink)
From Thomas 'PointedEars' Lahn <PointedEars@web.de>
Organization PointedEars Software (PES)
Date 2013-01-01 01:58 +0100
Subject Re: Question on form validation
Newsgroups comp.lang.javascript
References <be8abd23-af86-48c7-be3f-a751ce6e574f@googlegroups.com> <2012123116071843163-michaelfilbin@gmailcom>
Followup-To comp.lang.javascript

Followups directed to: comp.lang.javascript

Show all headers | View raw


Please do not top-post, see <http://jibbering.com/faq/#posting>,
alternatively <http://PointedEars.de/scripts/faq/cljs/#posting>.

Mike Filbin wrote:

> On 2012-12-19 14:57:35 +0000, bravesplace@gmail.com said:
>> I use the following to determine if a field is blank and to alert them
>> the field is required:
>> 
>> if (Form1.FieldName.value == "")
>>   {
>>     alert("Please enter a value for the  FIELDNAME field.");
>>     Form1.FieldName.focus();
>>     return (false);
>>   }
>> 
>> How can I use a LIKE type of statement so if they use a word we cannot
>> allow such as "Stupid", I can advise them the word is not permitted?
> 
> Can you move your validation server-side?

The validation code should be duplicated on, not moved to, the server side.  
In the best case there will be a server-side framework that generates the 
client-side code from server-side code.

Because client-side validation can save unnecessary roundtrips to the 
server, improving user experience and network/server performance at the same 
time.  Web applications 101.

> If your form is rendered statically,

You have earned one Bullshit Bingo point for “rendered statically”.  What 
you perhaps meant to say was “_generated_ statically”.  But that does not 
matter because:

> the user can disable JavaScript to bypass your validation script.

The user can disable client-side script support in any case, or their user 
agent might not be capable of executing the script code (for various 
reasons).  That is why client-side validation helps, but does not suffice.

> Also, just a quick tip. Cache your reference to 'Form1.FieldName'. It is
> generally bad practice to resolve the same DOM node twice. You can cache
> it like so:
> 
> var field = Form1.FieldName;

However, the proper, backwards-compatible and standards-compliant form is

  var field = document.forms["Form1"].elements["FieldName"];

whereas most of this is unnecessary if you pass the reference to the FORM 
element node with “this”:

  function checkForm (form)
  {
    var field = form.elements["FieldName"];
    // …
  }

  <form … onsubmit="return checkForm(this)">
    …
  </form>

DOM 101.

Finally, you failed to address the question.  The simple and correct answer 
is, of course, regular expressions:

  if (/\bstupid\b/i.test(field.value))
  {
    window.alert("The word 'stupid' is forbidden here.");
    return false;
  }

However, if this is to prevent abuse, like spam, it is not going to be 
successful.  Spammers rarely submit from the user perspective, they send 
HTTP requests.  Which is why you can handle form abuse successfully only 
server-side.


PointedEars
-- 
When all you know is jQuery, every problem looks $(olvable).

Back to comp.lang.javascript | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Question on form validation bravesplace@gmail.com - 2012-12-19 06:57 -0800
  Re: Question on form validation Stefan Weiss <krewecherl@gmail.com> - 2012-12-19 16:20 +0100
  Re: Question on form validation Danny <dann90038@gmail.com> - 2012-12-19 13:38 -0800
  Re: Question on form validation Mike Filbin <michael.filbin@gmail.com> - 2012-12-31 16:07 -0700
    Re: Question on form validation Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2013-01-01 01:58 +0100
      Re: Question on form validation "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2013-01-01 11:35 +0100

csiph-web