Difference between revisions of "Learning PHP (2)"

From Wiki @ Karl Jones dot com
Jump to: navigation, search
(HTML special character handling)
Line 56: Line 56:
 
See [http://code.karljones.com/php/htmlspecialchars/ Online example]
 
See [http://code.karljones.com/php/htmlspecialchars/ Online example]
  
 +
== GET method ==
 +
 +
<pre>
 +
<?php
 +
echo htmlspecialchars ( $_GET['firstname'] ) ;
 +
?> 
 +
<hr />
 +
<?php
 +
echo htmlspecialchars ( $_GET['email'] ) ;
 +
?> 
 +
</pre>
 
== See Also ==
 
== See Also ==
  

Revision as of 18:01, 3 September 2015

This article contains examples of PHP.

Timestamp

PHP provides the time function, which returns the time (from the server clock).

The time can be formatted and used in a variety of ways.

Code snippet:

<p><?php echo time(); ?></p>

Observe how the above code snippet mixes HTML with PHP code islands.

View online.

Use your browser's View Source or Inspect Element to confirm that the web page's source code contains only HTML, no PHP.

See [time] for documentation, Timestamp for general information.

Date

PHP provides the date() function, which returns date and time.

The date and time can be formatted and used in a variety of ways.

Code snippet:

<p><?php echo date("Y/m/d"); ?></p>
<p><?php echo date("l"); ?></p>

Observe how the above code snippet mixes HTML with PHP code islands.

View online.

Use your browser's View Source or Inspect Element to confirm that the web page's source code contains only HTML, no PHP.

See PHP date for more information.

HTML special character handling

Warning: this topic is critical to web security.

Always use htmlspecialchars (or some equivalent technology) when processing user input. Always, always, always.

PHP provides a function named htmlspecialchars which handles special HTML characters.

Handles, in this case, includes replacing dangerous HTML with safe HTML.

See PHP htmlspecialchars function.

See Online example

GET method

	<?php		
		echo htmlspecialchars ( $_GET['firstname'] ) ;
	?>  
<hr />
	<?php		
		echo htmlspecialchars ( $_GET['email'] ) ;
	?>  

See Also

External links

Documentation

Tutorials