Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #2210

Re: Form fields to database and back?

From Jerry Stuckle <jstucklex@attglobal.net>
Newsgroups comp.lang.php
Subject Re: Form fields to database and back?
Date 2011-06-16 23:50 -0400
Organization A noiseless patient Spider
Message-ID <iteits$k2c$1@dont-email.me> (permalink)
References <j48lv6prpshk57ora2dsp6b2lvp16vkvtu@4ax.com> <ite935$1b5$1@dont-email.me> <plelv6lp4m78uv2tg5mjtm9bd5f13douk5@4ax.com>

Show all headers | View raw


On 6/16/2011 10:34 PM, bobmct wrote:
> On Thu, 16 Jun 2011 21:02:23 -0400, Jerry Stuckle
> <jstucklex@attglobal.net>  wrote:
>
>> It depends on what the problem is - which is why you're probably finding
>> conflicting answers.  Your question is too vague for a meaningful answer.
>>
>> First of all, it it ASCII, UTF-8 or some other character set?  It does
>> make a difference, and you want everything (the web page, PHP and MySQL
>> to agree).
>>
>> Second of all, how are you storing and retrieving the information?  Then
>> how are you displaying it?
>>
>> Generally, text information should be stored in the database in text
>> fields, using the appropriate charset and collation.
>>
>> But to give you a good answer requires a lot more information.
>
> Good points.  I should have been more clear.
>
> The fields(s) in the Mysql database aredefined as  varchar(255)
>
> A typical field the user would enter would be like this:
>
> prd ="^ptmdtr-slb.bna.com^";
>
> I need to store it in the db field then be able to retrieve it and
> redisplay it exactly as entered.
>
> Currently I am using:
> $fld = htmlspecialchars_decode($fld);
> $fld = addslashes($fld);
>
> update table set field_name = '$fld'
>
> To retrieve and redisplay I use:
> $fld = $row['field_name'];
> $fld = htmlspecialchars($fld);
> $fld = stripslashes($fld);
>
> Now I know that I am missing something here so if any ofyou kind
> persons would suggest a "usual' sequence of functions to use to
> accomplsih this I'd be mighty greatful.
>
> Thanks
>

A varchar field is great, as long as you're using the same charset all 
the way through.  But there are some other problems in your code:

First of all, you shouldn't be using htmlspecialchars_decode() - you do 
not get an encoded string from the browser; it's already been handled.

Second of all, addslashes() is definitely the WRONG function to use - 
and has been for years.  Before storing in the database, you should use 
mysql_real_escape_string($fld).

When you get the data from the database, you should not be using 
stripslashes().  There's no need.

Finally, when you go to display the data, you do want to use 
htmlspecialchars(), or possibly better for your needs, htmlentities().

See if that doesn't work better.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-16 20:36 -0400
  Re: Form fields to database and back? The Natural Philosopher <tnp@invalid.invalid> - 2011-06-17 01:43 +0100
    Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 21:03 -0400
  Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 21:02 -0400
    Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-16 22:34 -0400
      Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 23:50 -0400
        Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-17 07:09 -0400
          Re: Form fields to database and back? bobm3@worthless.info - 2011-06-17 15:18 +0000
            Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-17 16:44 -0400
      Re: Form fields to database and back? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-06-17 13:28 +0200
      Re: Form fields to database and back? Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-06-17 22:03 +0200
        Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-17 19:52 -0400
          Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-17 21:01 -0400
            Re: Form fields to database and back? Captain Paralytic <paul_lautman@yahoo.com> - 2011-06-22 09:05 -0700
              Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-22 13:15 -0400
          Re: Form fields to database and back? Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-06-18 08:35 +0200

csiph-web