Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #17772 > unrolled thread

Question on form validation

Started bybravesplace@gmail.com
First post2012-12-19 06:57 -0800
Last post2013-01-01 11:35 +0100
Articles 6 — 6 participants

Back to article view | Back to comp.lang.javascript


Contents

  Question on form validation bravesplace@gmail.com - 2012-12-19 06:57 -0800
    Re: Question on form validation Stefan Weiss <krewecherl@gmail.com> - 2012-12-19 16:20 +0100
    Re: Question on form validation Danny <dann90038@gmail.com> - 2012-12-19 13:38 -0800
    Re: Question on form validation Mike Filbin <michael.filbin@gmail.com> - 2012-12-31 16:07 -0700
      Re: Question on form validation Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2013-01-01 01:58 +0100
        Re: Question on form validation "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2013-01-01 11:35 +0100

#17772 — Question on form validation

Frombravesplace@gmail.com
Date2012-12-19 06:57 -0800
SubjectQuestion on form validation
Message-ID<be8abd23-af86-48c7-be3f-a751ce6e574f@googlegroups.com>
I use the following to determine if a field is blank and to alert them the field is required:

if (Form1.FieldName.value == "")
  {
    alert("Please enter a value for the  FIELDNAME field.");
    Form1.FieldName.focus();
    return (false);
  }

How can I use a LIKE type of statement so if they use a word we cannot allow such as "Stupid", I can advise them the word is not permitted?

[toc] | [next] | [standalone]


#17773

FromStefan Weiss <krewecherl@gmail.com>
Date2012-12-19 16:20 +0100
Message-ID<kaslv2$j9m$1@news.albasani.net>
In reply to#17772
On 2012-12-19 15:57, bravesplace@gmail.com wrote:
> if (Form1.FieldName.value == "")
>   {
>     alert("Please enter a value for the  FIELDNAME field.");
>     Form1.FieldName.focus();
>     return (false);
>   }
> 
> How can I use a LIKE type of statement so if they use a word we
> cannot allow such as "Stupid", I can advise them the word is not
> permitted?

To search for a substring, you can use haystack.indexOf(needle). Convert
the values of haystack and needle to lowercase to make the test case
insensitive.

For example:

  var haystack = "you guys are stupid!";
  var needle = "stupid";
  if (haystack.indexOf(needle) > -1) {
      //...
  }

To match more complicated patterns, you can use regular rexpressions.
They are very powerful, but too complicated to explain here in detail.

If you're trying to implement an effective bad word filter, you're going
to have to do a LOT more work than just matching strings. Users can get
very creative in bypassing such filters (think h4x0r-style text,
deliberate misspellings, similar-looking characters from other
alphabets, etc).

Checks like this should also be done on the server, not in the browser.


- stefan

[toc] | [prev] | [next] | [standalone]


#17777

FromDanny <dann90038@gmail.com>
Date2012-12-19 13:38 -0800
Message-ID<4a1c15a4-bf9e-4d70-a805-0040e696c88b@googlegroups.com>
In reply to#17772
As Stefan pointed out, I'd suggest using a regexp, as in -> http://www.webdevout.net/test?0v&raw

In that example the words I used there you can see in Line 8

[toc] | [prev] | [next] | [standalone]


#17899

FromMike Filbin <michael.filbin@gmail.com>
Date2012-12-31 16:07 -0700
Message-ID<2012123116071843163-michaelfilbin@gmailcom>
In reply to#17772
Can you move your validation server-side? If your form is rendered 
statically, the user can disable JavaScript to bypass your validation 
script. Also, just a quick tip. Cache your reference to 
'Form1.FieldName'. It is generally bad practice to resolve the same DOM 
node twice. You can cache it like so:

var field = Form1.FieldName;

And then refer to it as

 // Use triple equal for type corherced comparisons. Double euqals can 
give unexpected results
if (field.value === ""){
 	…
	field.focus();
	...
} else {
	...
}

On 2012-12-19 14:57:35 +0000, bravesplace@gmail.com said:

> I use the following to determine if a field is blank and to alert them 
> the field is required:
> 
> if (Form1.FieldName.value == "")
>   {
>     alert("Please enter a value for the  FIELDNAME field.");
>     Form1.FieldName.focus();
>     return (false);
>   }
> 
> How can I use a LIKE type of statement so if they use a word we cannot 
> allow such as "Stupid", I can advise them the word is not permitted?

	

[toc] | [prev] | [next] | [standalone]


#17905

FromThomas 'PointedEars' Lahn <PointedEars@web.de>
Date2013-01-01 01:58 +0100
Message-ID<2054338.ZTifN9JQ4c@PointedEars.de>
In reply to#17899
Please do not top-post, see <http://jibbering.com/faq/#posting>,
alternatively <http://PointedEars.de/scripts/faq/cljs/#posting>.

Mike Filbin wrote:

> On 2012-12-19 14:57:35 +0000, bravesplace@gmail.com said:
>> I use the following to determine if a field is blank and to alert them
>> the field is required:
>> 
>> if (Form1.FieldName.value == "")
>>   {
>>     alert("Please enter a value for the  FIELDNAME field.");
>>     Form1.FieldName.focus();
>>     return (false);
>>   }
>> 
>> How can I use a LIKE type of statement so if they use a word we cannot
>> allow such as "Stupid", I can advise them the word is not permitted?
> 
> Can you move your validation server-side?

The validation code should be duplicated on, not moved to, the server side.  
In the best case there will be a server-side framework that generates the 
client-side code from server-side code.

Because client-side validation can save unnecessary roundtrips to the 
server, improving user experience and network/server performance at the same 
time.  Web applications 101.

> If your form is rendered statically,

You have earned one Bullshit Bingo point for “rendered statically”.  What 
you perhaps meant to say was “_generated_ statically”.  But that does not 
matter because:

> the user can disable JavaScript to bypass your validation script.

The user can disable client-side script support in any case, or their user 
agent might not be capable of executing the script code (for various 
reasons).  That is why client-side validation helps, but does not suffice.

> Also, just a quick tip. Cache your reference to 'Form1.FieldName'. It is
> generally bad practice to resolve the same DOM node twice. You can cache
> it like so:
> 
> var field = Form1.FieldName;

However, the proper, backwards-compatible and standards-compliant form is

  var field = document.forms["Form1"].elements["FieldName"];

whereas most of this is unnecessary if you pass the reference to the FORM 
element node with “this”:

  function checkForm (form)
  {
    var field = form.elements["FieldName"];
    // …
  }

  <form … onsubmit="return checkForm(this)">
    …
  </form>

DOM 101.

Finally, you failed to address the question.  The simple and correct answer 
is, of course, regular expressions:

  if (/\bstupid\b/i.test(field.value))
  {
    window.alert("The word 'stupid' is forbidden here.");
    return false;
  }

However, if this is to prevent abuse, like spam, it is not going to be 
successful.  Spammers rarely submit from the user perspective, they send 
HTTP requests.  Which is why you can handle form abuse successfully only 
server-side.


PointedEars
-- 
When all you know is jQuery, every problem looks $(olvable).

[toc] | [prev] | [next] | [standalone]


#17906

From"Evertjan." <exxjxw.hannivoort@inter.nl.net>
Date2013-01-01 11:35 +0100
Message-ID<XnsA13B75E13F794eejj99@194.109.133.133>
In reply to#17905
Thomas 'PointedEars' Lahn wrote on 01 jan 2013 in comp.lang.javascript:

> The validation code should be duplicated on, not moved to, the server
> side.  In the best case there will be a server-side framework that
> generates the client-side code from server-side code.

In the case of serverside Javascript, on topic on this NG, 
such duplication involves no "generation".

Both scripts can be be exactly the same, 
if you are carefull to write cross-engine compatible script.

-- 
Evertjan.
The Netherlands.
(Please change the x'es to dots in my emailaddress)

[toc] | [prev] | [standalone]


Back to top | Article view | comp.lang.javascript


csiph-web