Skip to Content
Learning PHP & MySQL, 2nd Edition
book

Learning PHP & MySQL, 2nd Edition

by Michele E. Davis, Jon A. Phillips
August 2007
Beginner
428 pages
8h 59m
English
O'Reilly Media, Inc.
Content preview from Learning PHP & MySQL, 2nd Edition

Chapter 16. Validation and Error Handling

We’ve already discussed performing validation within our PHP code. In this chapter we’ll explore our options for validating form data before a form submission. We’ll also discuss what to do when validation fails, and how to process other errors. We can check information on the client side in the user’s browser with JavaScript. We can also check the data when it’s submitted directly in PHP.

There’s some information that can go out as part of a production error message that isn’t harmful for end users. For example, it’s OK to say that you’re having a problem connecting to your database. However, you don’t want to reveal more information than is necessary in any error messages that may go out to end users. You don’t want to disclose the IP address of your database and certainly not the username that was attempted when you tried to connect. Both of those could aid a potential attacker in breaking into the database when it comes back online.

Validating User Input with JavaScript

On the client side, your best tool for validating data is JavaScript. JavaScript is different than PHP because it’s designed to execute in the user’s browser instead of on the server. Because it executes from the client’s computer, JavaScript isn’t allowed to access anything that could be a security risk, such as the local filesystem or network resources. JavaScript is primarily used in web pages. Although its name sounds like Java, it has no relationship to it.

Since this ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Learning PHP, MySQL & JavaScript, 5th Edition

Learning PHP, MySQL & JavaScript, 5th Edition

Robin Nixon
Learning PHP and MySQL

Learning PHP and MySQL

Michele E. Davis, Jon A. Phillips

Publisher Resources

ISBN: 9780596514013Errata Page