Re: Form Design Advice - Mailing list pgsql-novice

From Ross Gohlke
Subject Re: Form Design Advice
Date
Msg-id 50192.4.62.156.229.1109954376.squirrel@4.62.156.229
Whole thread Raw
In response to Re: Form Design Advice  (Bruno Wolff III <bruno@wolff.to>)
Responses Re: Form Design Advice
List pgsql-novice
>>Code your form manually with the proper element names. Add a hidden
element for each visible element to pass the field's type for validation

>>purposes.
>
> This should be in an additional table in the database, not on the form.
Otherwise the end users can send back incorrect types to check against
which could potentially be a security issue.

I'm not sure I understand. How could a user send incorrect data types if
the types are included as hidden fields? Since the variables are
declared as coming from $_POST, they cannot send anything in the URL.






pgsql-novice by date:

Previous
From: Bruno Wolff III
Date:
Subject: Re: Form Design Advice
Next
From: Colin McGuigan
Date:
Subject: Re: Form Design Advice