if(count($_POST)>0) { /* Form Required Field Validation / foreach($_POST as $key=>$value) {
if(empty($_POST[$key])) {
$message = ucwords($key) . " field is required"; break; } } / Password Matching Validation */
if($_POST['password'] != $_POST['confirm_password']){ $message = 'Passwords should be same '; }
/* Email Validation */ if(!isset($message)) { if (!filter_var($_POST["userEmail"], FILTER_VALIDATE_EMAIL)) { $message = "Invalid UserEmail"; }
}
/* Validation to check if gender is selected */ if(!isset($message)) { if(!isset($_POST["gender"])) { $message = " Gender field is required"; } }
if(!isset($message)) { require_once("dbcontroller.php"); $db_handle = new DBController();
$query = "INSERT INTO users (username, name, last_name, gender, BirthMonth, BirthDay, BirthYear, Country, email, password, phone) VALUES ('" . $_POST["userName"] . "', '" . $_POST["name"] . "', '" . $_POST["lastName"] . "', '" .$_POST["gender"] . "', '" . $_POST["BirthMonth"] . "', '" . $_POST["BirthDay"] . "' , '" . $_POST["BirthYear"] ."','". $_POST["Country"] ."', '" . $_POST["userEmail"]. "','" . $_POST["password"]. "','".$_POST["Phone"]. "')"; $result = $db_handle->insertQuery($query);
编辑:将代码格式化为visib; e错误更好。提前感谢任何回答的人。
答案 0 :(得分:0)
电子邮件验证:
除了检查诸如' @'之类的常见符号之外和字母数字一样,您还必须在开始时检查空格/制表符,最重要的是使用htmlspecialchars()
将输入的输入转换为:
function reduceInput($data) {
$data = trim($data);
$data = stripslashes($data);
$data = htmlspecialchars($data);
return $data;
}
拨打reduceInput()
上的$_POST['userEmail']
功能,然后使用filter_var()
功能对其进行验证。
答案 1 :(得分:0)
我明白你的意思是不要将利用字符串传递给数据库?您不必为此验证这些值。有一个php函数可以将字符串安全地传递给您的数据库。那就是它:
mysqli_real_escape_string($mysqli_object, $_POST['userName']);
但是,如果您要验证自己的电子邮件和用户名,请执行以下操作:
if (ctype_alnum($nick)==false) exit(0);// this makes your nick can only contain letters and numbers
$emailB = filter_var($email, FILTER_SANITIZE_EMAIL);//this sanitizes your email
if ((filter_var($emailB, FILTER_VALIDATE_EMAIL)==false) || ($emailB!=$email)) exit(0);//this validates your email
答案 2 :(得分:0)
您要检查您的电子邮件是否在数据库中退出,然后使用此代码。在此行之后添加此代码。
/* Email Validation */ if(!isset($message)) { if(!filter_var($_POST["userEmail"], FILTER_VALIDATE_EMAIL))
{ $message = "Invalid UserEmail"; }
}
你的数据库连接需要为此连接,所以首先连接这个
require_once("dbcontroller.php"); $db_handle = new DBController();
希望你的连接正常,所以这段代码会检查
<?php
$sql = "SELECT anyfiled FROM yourtable WHERE email = " .$_POST['userEmail'];
$select = mysqli_query($con, $sql);
$row = mysqli_fetch_assoc($select);
if (mysqli_num_rows($select) > 0) {
$message = "exist";
}
?>