Path: csiph.com!v102.xanadu-bbs.net!xanadu-bbs.net!news.mixmin.net!eweka.nl!hq-usenetpeers.eweka.nl!border3.nntp.ams.giganews.com!border1.nntp.ams.giganews.com!nntp.giganews.com!feeder1.cambriumusenet.nl!feed.tweaknews.nl!193.141.40.65.MISMATCH!npeer.de.kpn-eurorings.net!npeer-ng0.de.kpn-eurorings.net!newsfeed.arcor.de!newsspool4.arcor-online.net!news.arcor.de.POSTED!not-for-mail Content-Type: text/plain; charset="ISO-8859-1" Message-ID: <2610175.x4FWaXcEle@PointedEars.de> From: Thomas 'PointedEars' Lahn Reply-To: Thomas 'PointedEars' Lahn Organization: PointedEars Software (PES) Date: Tue, 02 Oct 2012 22:26:18 +0200 User-Agent: KNode/4.4.11 Content-Transfer-Encoding: 7Bit X-Face: %i>XG-yXR'\"2P/C_aO%~;2o~?g0pPKmbOw^=NT`tprDEf++D.m7"}HW6.#=U:?2GGctkL,f89@H46O$ASoW&?s}.k+&. Followup-To: comp.lang.javascript MIME-Version: 1.0 Lines: 84 NNTP-Posting-Date: 02 Oct 2012 22:26:20 CEST NNTP-Posting-Host: b54d4d2c.newsspool3.arcor-online.net X-Trace: DXC=ZR:@YMgoca0T2Rfi6`76:4V3C1eaeRd1 X-Complaints-To: usenet-abuse@arcor.de Xref: csiph.com comp.lang.javascript:16322 Patricia Shanahan wrote: > I am writing a data collection application. It needs to run on as many > tablets and laptops as possible, so I'm writing it in HTML and > JavaScript. Although I cannot ask end users to buy a particular device, > I can ask them to install an up to date browser. > > The ultimate destination of the data is a spreadsheet on a workstation > controlled by the person doing the data entry, or one of their associates. > > The ideal, from my end users' point of view, would be a button they > could click that would send an e-mail to an address they enter with the > data attached in .csv format. You cannot do that client-side, so you will have to do it server-side. That is, have a server-side application compile the .csv and send the e-mail. Usually that would be the same server-side application that generated the client-side application in the first place. > I do understand that e-mail would not be the best way of getting the data > to a web server, but that is not the objective. Forwarding the data from > my web site to a user-specified e-mail address would require anti-spam > precautions, and be generally undesirable. If that is a concern, users of the application need to be authenticated before they can use that function (see also [OWASP]). Only shifting the load from the server to the client is not a solution. In fact, it has the potential to make matters worse. Client computers (including mobile devices) are usually much less protected, thus more easily compromised, than servers. > I've done web searches, and the closest I've been able to get is to fold > the data into a mailto URL as the message body, not an attachment. Technically, an e-mail attachment is a part of the message body of a multi- part message, following a delimiter line, own header and usually a Base64- encoded message-part body (see [RFC2046]); so, in theory, it could work. But I would not recommend it for production. In fact, security measures might prevent it. > I would be length limited by the Internet Explorer 2083 char URL limit, > and I think I would also have to quote URL special characters. Apparently there are exceptions for certain supported URI schemes, such as `data:'. [SO] There might be one for `mailto:' as well. However, a suitable MUA will need to be installed and configured at the client for this to work, which you should not make a requirement. > Another option is to just display the data and invite the user to > select and copy. The data could then be pasted into the body of an > e-mail, or into a text file in an editor window. I believe that would > work, but involves more end user busy work than is ideal. Yes, in a Web application you should make best use of the *Web* first. > I am very new to JavaScript, so I'm really hoping there is a better way > of doing this that I have just not found. Client-side there is nothing better than that, but it does not mean that it cannot be done using an ECMAScript implementation server-side. HTH PointedEars ___________ [OWASP] The Open Web Application Security Project: Authentication Cheet Sheet. (updated: 2012-09-28) [RFC2046] Freed, N., Borenstein, N.: Multipurpose Internet Mail Extensions (MIME) Part Two: Media Types. November 1996. [SO] StackOverflow: What is the maximum length of a URL? (updated: 2012-07-12) -- Use any version of Microsoft Frontpage to create your site. (This won't prevent people from viewing your source, but no one will want to steal it.) -- from (404-comp.)