Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #2226

Re: Form fields to database and back?

Message-Id <1655216.aK4W3vaeNJ@PointedEars.de>
From Thomas 'PointedEars' Lahn <PointedEars@web.de>
Organization PointedEars Software (PES)
Date 2011-06-17 22:03 +0200
Subject Re: Form fields to database and back?
Newsgroups comp.lang.php
References <j48lv6prpshk57ora2dsp6b2lvp16vkvtu@4ax.com> <ite935$1b5$1@dont-email.me> <plelv6lp4m78uv2tg5mjtm9bd5f13douk5@4ax.com>
Followup-To comp.lang.php

Followups directed to: comp.lang.php

Show all headers | View raw


bobmct wrote:

> A typical field the user would enter would be like this:
> 
> prd ="^ptmdtr-slb.bna.com^";
> 
> I need to store it in the db field then be able to retrieve it and
> redisplay it exactly as entered.
> 
> Currently I am using:
> $fld = htmlspecialchars_decode($fld);
> $fld = addslashes($fld);
> 
> update table set field_name = '$fld'

This does not make sense.  Either you are writing a CMS, then you should 
store all markup verbatim (after removing potentially unwanted elements).  
Or you are not, then you should not be receiving markup in the first place.

Unless you write for debugging, you could combine the calls:

  $fld = addslashes(htmlspecialchars($fld));

But not even debugging merits two assignments here.  (Note that this is just 
an example.  Do not use addslashes() here.)

If this is just a bad example, then consider this: You should avoid using 
such PHP built-ins to escape parts of a database query.  addslashes() is 
inadequate() to the task.  Use extension-provided functions, like 
mysql_real_escape_string() or (better) prepared statements (as supported 
e.g. by PDO, MySQLi, and sqlsrv, and implemented e.g. by Zend Framework).
 
> To retrieve and redisplay I use:
> $fld = $row['field_name'];
> $fld = htmlspecialchars($fld);
> $fld = stripslashes($fld);

I do not see why stripslashes() is needed (other than to compensate for the 
pointless addslashes() before).  htmlspecialchars() is only needed in the 
output (so unless you are displaying a value twice, `echo' the return value 
of htmlspecialchars() directly – unless your template engine/framework 
already does that for you before, which it should be able to if it is any 
good), and you should provide suitable additional parameters then (so that, 
e.g., Unicode characters can be properly decoded and referred in the 
markup).

Of course, you do not need or want to escape all dynamically generated 
content, only where it matters (given a proper character encoding, 
especially one that is the same in the database and the generated document, 
and you making sure that no unwanted HTML is stored/retrieved in the first 
place, there is no need to escape the generated content of elements.)  Not 
trying to escape things that do not need to be escaped can have positive 
impact on the performance of a Web application (if you know the value is an 
int – as made sure by a properly designed interface –, you don't have to 
treat it like a string).
 

PointedEars
-- 
Danny Goodman's books are out of date and teach practices that are
positively harmful for cross-browser scripting.
 -- Richard Cornford, cljs, <cife6q$253$1$8300dec7@news.demon.co.uk> (2004)

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-16 20:36 -0400
  Re: Form fields to database and back? The Natural Philosopher <tnp@invalid.invalid> - 2011-06-17 01:43 +0100
    Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 21:03 -0400
  Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 21:02 -0400
    Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-16 22:34 -0400
      Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 23:50 -0400
        Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-17 07:09 -0400
          Re: Form fields to database and back? bobm3@worthless.info - 2011-06-17 15:18 +0000
            Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-17 16:44 -0400
      Re: Form fields to database and back? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-06-17 13:28 +0200
      Re: Form fields to database and back? Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-06-17 22:03 +0200
        Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-17 19:52 -0400
          Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-17 21:01 -0400
            Re: Form fields to database and back? Captain Paralytic <paul_lautman@yahoo.com> - 2011-06-22 09:05 -0700
              Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-22 13:15 -0400
          Re: Form fields to database and back? Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-06-18 08:35 +0200

csiph-web