|
Posted by Geoff Berrow on 10/11/55 11:39
Message-ID: <db2dnQWwkpylNnvenZ2dnUVZ_tadnZ2d@comcast.com> from Jerry
Stuckle contained the following:
>> Name all the boxes 'del[]' When posted the items to be deleted will be
>> in an array and you can loop through it and delete them.
>>
>
>Geoff,
>
>And what happens if I come along and post a form back to your page with:
>
> <input type ='checkbox' name='del[]' value="1 OR 42=42">
>
>ALWAYS validate incoming data - even if it's from a checkbox!
Jerry...you're not thinking this through. The person already has
permission to delete the data.
--
Geoff Berrow (put thecat out to email)
It's only Usenet, no one dies.
My opinions, not the committee's, mine.
Simple RFDs http://www.ckdog.co.uk/rfdmaker/
Navigation:
[Reply to this message]
|