Jump to content

Recommended Posts

I have a comment textarea on a form. To validate it i'm going to use php regular expressions. Anyone know a good reg exp to use? Or what characters should I allow/not allow? The only one I was thinking would cause problems is "<" and ">". That would prevent html and php and others. Your comments/suggestions?
Link to comment
https://forums.phpfreaks.com/topic/3766-validating-comment-box/
Share on other sites

Be careful, however. This strips tags, but does not strip quotes. If you're storing the comment in a database, you could open yourself up to a security problem. I urlencode the strings before storing them in the database, then use the following to display it later (note, I use smarty templates, but this should work for straight php as well) :

// "Fix" the free-form text and assign it to the template
if (get_magic_quotes_gpc()) {
$smarty->assign('impact', stripslashes(urldecode($impact)));
} else {
$smarty->assign('impact', urldecode($impact));
}

XenoPhage
Link to comment
https://forums.phpfreaks.com/topic/3766-validating-comment-box/#findComment-13095
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.