PHP Filter
PHP filters are used to validate and sanitize external input.
Validating data is determine if the data is in proper form.
Sanitizing data is remove any illegal character from the data.
The PHP filter extension has many of the functions needed for checking user input, and is designed to make data validation easier and quicker.
The filter_list() function can be used to list what the PHP filter extension offers
<table>
<tr>
<td>Filter Name</td>
<td>Filter ID</td>
</tr>
<?php
foreach(filter_list() as $id => $filter){
echo '<tr><td>' .$filter .'</td><td>' .filter_id($filter) . '</td></tr>';
}
?>
</table>
Many web application recieve external input.External input/data can be:
User input from a form
Cookies
Web Services data
Server variables
Database query results
The filter_var() function both validate and sanitize data.
The filter_var() function filters a single variable with a specified filter.It takes two pieces of data:
- The Variable you want to check
- The type of check to use
The following example uses the filter_var() funcion to remove all HTML tags from a string:
<?php
$str = "<h1>Hello World</h1>";
$newStr = filter_var($str, FILTER_SANITIZE_STRING);
echo $newStr; //Hello World
?>
The following example uses the filter_var() function to check if the variable $int is an integer.
<?php
$int = 100;
// if $int was set to 0, the function will return "Integer is not valid"
// filter_var($int, FILTER_VALIDATE_INT) ===0 it will work when you set 0 to $int
if(!filter_var($int, FILTER_VALIDATE_INT) === false){
echo("Integer is valid");
}else{
echo("Integer is not valid");
}
?>
The following example uses the filter_var() function to check if the variable $ip is a valid IP address
<?php
$ip = "127.0.0.1";
if(!filter_var(FILTER_VALIDATE_IP) === false){
echo("$ip is a valid IP address");
}else{
echo("$ip is not a valid IP address");
}
?>
The following example uses the filter_var() function to first remove all illegal characters from the $email variable, then check if it is a valid email address
<?php
$email = "john.doe@example.com";
//remove all illegal characters from email
$email = filter_var($email, FILTER_SANITIZE_EMAIL);
// validate e-mail
if(!filter_var($email, FILTER_VALIDATE_EMAIL) === false){
echo("$email is a valid email address");
}else{
echo("$email is not a valid email address");
}
?>
The following example uses the filter_var() function to first remove all illegal characters from a URL, then check if $url is a valid URL
<?php
$url = "http://www.w3schools.com";
//remove all illegal characters from a url
$url = filter_var($url, FILTER_SANITIZE_URL);
// validate url
if(!filter_var($url, FILTET_VALIDATE_URL) === false){
echo("$url is a valid URL");
}else{
echo("$url is not a valid URL");
}
?>
The following example uses the filter_var() function to check if a variable is both of type INT, and between 1 and 200
<?php
$int = 122;
$min = 1;
$max = 200;
if(filter_var($int, FILTER_VALIDATE_INT, array("options" => array("min_range" => $min, "max_range" => $max))) === false){
echo("Variable value is not within the legal range");
}else{
echo("Variable value is within the legal range");
}
?>
The following example uses the filter_var() function to checkt if the variable $ip is a valid IPv6 address:
<?php
$ip = "2001:0db8:85a3:08d3:1319:8a2e:0370:7334";
if(!filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_IPV6) === false){
echo("$ip is a valid IPv6 address");
}else{
echo("$ip is not a valid IPv6 address");
}
?>
The following example uses the filter_var() function to check if the variable $url is a URL with a querystring:
<?php
$url = "http://www.w3schools.com";
if(!filter_var($url, FILTER_VALIDATE_URL, FILTER_FLAG_QUERY_REQUIRED) === false){
echo("$url is a valid URL");
}else{
echo($url is not a valid URL);
}
?>
The following example uses the filter_var() function to sanitize a string.It will both remove all HTML tags, and all characters with ASCII value > 127, from the string:
<?php
$str = "<h1>Hello WorldØÅ</h1>";
$newStr = filter_var($str, FILTER_SANITIZE_STRING, FILTER_FLAG_STRIP_HIGH);
echo $newStr;
?>
PHP Filter的更多相关文章
- django 操作数据库--orm(object relation mapping)---models
思想 django为使用一种新的方式,即:关系对象映射(Object Relational Mapping,简称ORM). PHP:activerecord Java:Hibernate C#:Ent ...
- JavaWeb——Filter
一.基本概念 之前我们用一篇博文介绍了Servlet相关的知识,有了那篇博文的知识积淀,今天我们学习Filter将会非常轻松,因为Filter有很多地方和Servlet类似,下面在讲Filter的时候 ...
- 以bank account 数据为例,认识elasticsearch query 和 filter
Elasticsearch 查询语言(Query DSL)认识(一) 一.基本认识 查询子句的行为取决于 query context filter context 也就是执行的是查询(query)还是 ...
- AngularJS过滤器filter-保留小数,小数点-$filter
AngularJS 保留小数 默认是保留3位 固定的套路是 {{deom | number:4}} 意思就是保留小数点 的后四位 在渲染页面的时候 加入这儿个代码 用来精确浮点数,指定小数点 ...
- 挑子学习笔记:特征选择——基于假设检验的Filter方法
转载请标明出处: http://www.cnblogs.com/tiaozistudy/p/hypothesis_testing_based_feature_selection.html Filter ...
- [模拟电路] 2、Passive Band Pass Filter
note: Some articles are very good in http://www.electronics-tutorials.ws/,I share them in the Cnblog ...
- AngularJS过滤器filter-时间日期格式-渲染日期格式-$filter
今天遇到了这些问题索性就 写篇文章吧 话不多说直接上栗子 不管任何是HTML格式还是JS格式必须要在 controller 里面写 // new Date() 获取当前时间 yyyy-MM-ddd ...
- 《ES6基础教程》之 map、forEach、filter indexOf 用法
1,map,对数组的每个元素进行一定操作,返回一个新的数组. var oldArr = [{first_name:"Colin",last_name:"Toh" ...
- 1. 使用Filter 作为控制器
最近整理一下学习笔记,并且准备放到自己的博客上.也顺便把Struts2 复习一遍 1. MVC 设计模式概览 实现 MVC(Model.View.Controller) 模式的应用程序由 3 大部分构 ...
- angularjs之filter过滤器
现在公司用ionic,就是基于angularjs封装了一些api用于webapp,最近用的angularjs的filter确实省了很多代码,现在总结一下! ng比较鸡肋的过滤器,这里就一笔带过吧!鸡汤 ...
随机推荐
- BT5更新源
感谢http://blog.csdn.net/seaos/article/details/7064136终于找到更新成功的源了 下面简单介绍步骤吧 gedit /etc/apt/sources.lis ...
- Sui 弹框固定
SUI是一套基于bootstrap开发的前端组件库,同时它也是一套设计规范,可以非常方便的设计和实现精美的页面,是一个简单易用.功能强大的UI库.自己在使用sui过程之中,总是忘记它的一些Api,今天 ...
- Huffman树与编码的简单实现
好久没写代码了,这个是一个朋友问的要C实现,由于不会C,就用JAVA写了个简单的.注释掉的代码属性按照原来朋友发的题里带的参数,发现没什么用就给注释掉了. package other; import ...
- ODBC 小例
#include "stdafx.h"#include <windows.h>#include <stdio.h>#include <iostream ...
- EF Code First:实体映射,数据迁移,重构(1)
一.前言 经过EF的<第一篇>,我们已经把数据访问层基本搭建起来了,但并没有涉及实体关系.实体关系对于一个数据库系统来说至关重要,而且EF的各个实体之间的联系,实体之间的协作,联合查询等也 ...
- Ubuntu 设置su密码
如果之前安装时没有设置root密码,可以如下设置: 命令窗口中输入:sudo passwd [sudo] password for 用户名: 这里输入你sudo 的密码输入新的 UNIX 密码: 重 ...
- (转)onTouchEvent方法的使用
(转)onTouchEvent方法的使用 手机屏幕事件的处理方法onTouchEvent.该方法在View类中的定义,并且所有的View子类全部重写了该方法,应用程序可以通过该方法处理手机屏幕的触 ...
- js 替换 当前URL 特定参数
js 替换 当前URL 特定参数 2012-12-24 20:45:53| 分类: JS&JQuery |举报 |字号 订阅 //替换指定传入参数的值,paramName为参数,repl ...
- 二模 (3) day2
第一题: 题目大意:(难以概括,就不贴了把.) 解题过程: 1.担心被精度问题恶心,就把平均数的地方乘了N,这样只有最后计算的时候才会是小数.. 2.数组保存的时候蛋疼的 没改成double.结果全部 ...
- NLTk
1.python的nltk中文使用和学习资料汇总帮你入门提高 http://blog.csdn.net/huyoo/article/details/12188573