Go to Post I'm impressed and incredibly amused that you found so many of Dave's evildoings, though granted, they aren't that hard to search out. - DCA Fan [more]
Home
Go Back   Chief Delphi > Technical > Programming
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Closed Thread
 
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 19-02-2004, 23:42
Robert Hafner's Avatar
Robert Hafner Robert Hafner is offline
FIRST Alumni
no team
 
Join Date: Mar 2003
Rookie Year: 2000
Location: Springfield. MA
Posts: 34
Robert Hafner is on a distinguished road
Send a message via AIM to Robert Hafner Send a message via MSN to Robert Hafner Send a message via Yahoo to Robert Hafner
database programming

I recently finished adding a scouting database to out teams website. Please go do everything you can to break it, then tell me how you did it, so I can fix it. www.team96.org/scouting/
  #2   Spotlight this post!  
Unread 20-02-2004, 00:14
deltacoder1020's Avatar
deltacoder1020 deltacoder1020 is offline
Computer Guy
AKA: Dav
#1020 (The Indiana Prank Monkeys)
Team Role: Programmer
 
Join Date: Jan 2004
Location: Muncie, Indiana
Posts: 340
deltacoder1020 has a spectacular aura aboutdeltacoder1020 has a spectacular aura about
Send a message via AIM to deltacoder1020
Re: database programming

well, you probably shouldn't allow people to put HTML in the description boxes... try looking at the page for team 1020 to see what I mean.

you should run the PHP function strip_tags() on all incoming input from textboxes. also, you might considering running nl2br() on it after strip_tags to make newlines display correctly in html.
__________________
Team 1020, the Indiana Prank Monkeys (www.team1020.org)
  #3   Spotlight this post!  
Unread 20-02-2004, 00:38
Robert Hafner's Avatar
Robert Hafner Robert Hafner is offline
FIRST Alumni
no team
 
Join Date: Mar 2003
Rookie Year: 2000
Location: Springfield. MA
Posts: 34
Robert Hafner is on a distinguished road
Send a message via AIM to Robert Hafner Send a message via MSN to Robert Hafner Send a message via Yahoo to Robert Hafner
Re: database programming

First of all, you are my new hero. That was cool.

Anyways, I fixed that. Of course, your team will probably need to enter new information now, since I dropped the other stuff.

Thanks.
  #4   Spotlight this post!  
Unread 20-02-2004, 00:54
deltacoder1020's Avatar
deltacoder1020 deltacoder1020 is offline
Computer Guy
AKA: Dav
#1020 (The Indiana Prank Monkeys)
Team Role: Programmer
 
Join Date: Jan 2004
Location: Muncie, Indiana
Posts: 340
deltacoder1020 has a spectacular aura aboutdeltacoder1020 has a spectacular aura about
Send a message via AIM to deltacoder1020
Re: database programming

One of my current projects (non-FIRST, so it's sorta on hold) is designing an e-commerce site for shareware/independent commercial software, and you wouldn't believe how much validation form submissions go through. Suffice to say that just about any input is limited to only the exact characters you would need for a response to that. For instance, an email field is only allowed the characters "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVW XYZ@-_.0123456789", because those are the only characters one would need for an email address.

But the one thing you never want to let people do is submit HTML tags in any form that is going to be displayed back to the user.
__________________
Team 1020, the Indiana Prank Monkeys (www.team1020.org)
Closed Thread


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Scouting Database Robert Hafner General Forum 4 20-02-2004 23:37
Übergeeks scouting database, and the competitions Jeremy_Mc Scouting 10 09-03-2003 00:26
Division assignments now available in Team 340 database archiver 2001 13 24-06-2002 03:05
Playbook now included with Team 340 database archiver 2001 0 24-06-2002 01:33
We have to organize to win archiver 2001 18 24-06-2002 00:00


All times are GMT -5. The time now is 04:19.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi