Re: 2D array by POST
Jerry Stuckle <[email protected]> Sat, 20 May 2023 00:06:13 -0400
| Newsgroups | comp.lang.php |
|---|---|
| Organization | A noiseless patient Spider |
| Message-ID | <[email protected]> |
On 5/19/2023 9:30 PM, Arne Vajhøj wrote: > On 5/18/2023 5:44 PM, J.O. Aho wrote: >> On 5/18/23 23:38, The Doctor wrote: >>> In article <[email protected]>, >>> J.O. Aho <[email protected]> wrote: >>>> On 5/18/23 18:04, Liz Tuddenham wrote: >>>>> I need to send a 2-dimensional array from one file to another by POST. >>>>> The array is $item[][] with contents that are entirelyintegers. >>>>> >>>>> I have tried : >>>>> Print "<INPUT TYPE=hidden NAME=item[] VALUE=$item>"; >>>>> with >>>>> $item = stripslashes($_POST['item']); >>>>> but it does not work. >>>>> >>>>> Any suggestions? >>>> >>>> 1. use session, store the value in the session and then use it in the >>>> next page directly from the session. >>>> >>>> 2. serialize the variable and base64 encode the serialized data, post >>>> this in the form and then base64 decode and unserialize. >>>> >>> >>> Is base64 strong enugh? >> >> It's not about the encryption, it's about not making the html to break >> as you don't know what the serialized data may contain. >> >> if the data is sensitive or you want to avoid user manipulation of the >> data, then store the data in session and that is way it was number 1 >> of the suggestions. > > The concept of "page scope" or "view state" is well > known in some other technologies (like ASP.NET and JSF). > That may end up as a HTML hidden field like this. > > In such cases it should always be secured cryptographic > (MAC etc.). Frameworks that supports page scope / view state > via hidden field usually have this enabled by default. > > Given that this is not supported out of the box in PHP > (I have no idea whether any of the well known PHP MVC > frameworks offer such support), then it is not an > easy solution to implement. > > So using session absolutely looks like the path of least > resistance. > > But people should be aware that switching from page > scope to session scope is only transparent in 99.9% or > so of cases. There are (rare) cases where it will impact > functionality. > > Arne > > > > > If the data is sensitive, such as prices, it shouldn't even be sent to the user, encrypted or not. That's what the $_SESSION variable is for. -- ================== Remove the "x"'s from my email address Jerry Stuckle [email protected] ==================