Troy Cost
Troy Cost

Reputation: 67

PHP and secure forms

I am doing an exercise from the book PHP & MYSQL in easy steps. It involves an HTML form to update a row in a database then various PHP scripts to check the the input data for HTML code and make it into a secure format. However, the code just does not work the way the book says. I went to the publisher's website and downloaded the code example, but no joy.

Instead of a form with the name of the row below it, instead I get the form, then below that "No valid new name submitted". Then below that the current name of row in the table which I want to change. When I try to enter and submit data into the form it makes no difference. It displays exactly the same page. The code is below.

<!DOCTYPE HTML>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>Ensuring security
    </title>
</head>
<body>

<form action="secure.php" method="POST">
    <p>New Name : <input type="text" name="name">
        <input type="submit"></p></form>



<?php

require('../connect_db.php');


if (!empty($POST['name']) && !is_numeric($_POST['name'])) {
    $name = $POST['name'];

    $name = mysqli_real_escape_string($dbc, $name);
    $name = strip_tags($name);

    $q = 'UPDATE towels SET name "' . $name . '" WHERE id= 1';
    mysqli_query($dbc, $q);
} else {
    echo 'No valid new name submitted';
}

$q = 'SELECT * FROM towels WHERE id = 1 ';
$r = mysqli_query($dbc, $q);
while ($row = mysqli_fetch_array($r, MYSQLI_NUM)) {
    echo "<p>Name : $row[1] </p>";
}
mysqli_close($dbc);

I'd appreciate any ideas on this. I have spent about 3 hours and been on the publishers website, but I am still at square one.

Upvotes: 0

Views: 144

Answers (1)

Elon Than
Elon Than

Reputation: 9765

There is no superglobal array $POST so you have to change $POST['name'] to $_POST['name'].

PHP can't see that array so it evaluates !empty($POST['name']) as false and never executes code with update query.

And, like @BartFriederichs said, buy better book. I don't think you'll learn something valuable from current one.

Upvotes: 5

Related Questions