Improve company productivity with a Business Account.Sign Up

x
?
Solved

Losing $_GET variable inside if clause

Posted on 2009-07-08
9
Medium Priority
?
266 Views
Last Modified: 2013-12-13
Hi Experts!

the variable $_GET['subtask'] is not being posted to the database.

If I remove "isset($_POST['task'] from the if statement, it will work. But it has to be there.

Note that the other variables are being posted correctly to the database in both cases.

Thank you!
<? include 'inc/func.php'; ?>
<? include 'inc/dbc.php'; ?>
 
<? include 'inc/head.php'; ?>
 
<?
if(isset($_GET['subtask']) && isset($_POST['task'])){
	$q = "INSERT INTO tasks (task, parent_id, added) VALUES ('{$_POST['task']}', '{$_GET['subtask']}', NOW())";
	$r = mysql_query($q);
	redirect("index.php");    
}
?>
 
<? include 'inc/head.php'; ?>
 
<form action="new.php" method="post">
	<label>Task: </label><input name="task" id="task" type="text" />
    <br />
    <br />
    <input name="submit" id="submit" type="submit" value="Submit" />
</form>
 
<? include 'inc/foot.php'; ?>

Open in new window

0
Comment
Question by:AphX
  • 5
  • 3
9 Comments
 
LVL 61

Expert Comment

by:Kevin Cross
ID: 24804028
Try it like this:
(as indicated in the other question, this may need to be $_GET['task'] as well)
<? include 'inc/func.php'; ?>
<? include 'inc/dbc.php'; ?>
 
<? include 'inc/head.php'; ?>
 
<?
if(isset($_GET['subtask']) && isset($_POST['task'])){
        $q = "INSERT INTO tasks (task, parent_id, added) VALUES ('".$_POST['task']."', '".$_GET['subtask']."', NOW())";
        $r = mysql_query($q);
        redirect("index.php");    
}
?>
 
<? include 'inc/head.php'; ?>
 
<form action="new.php" method="post">
        <label>Task: </label><input name="task" id="task" type="text" />
    <br />
    <br />
    <input name="submit" id="submit" type="submit" value="Submit" />
</form>
 
<? include 'inc/foot.php'; ?>

Open in new window

0
 
LVL 2

Author Comment

by:AphX
ID: 24804114
Hi and thanks for fast response!

It didn't work. I can´t even echo $_GET['subtask'] inside the if clause. The exact same echo works outside the if clause.

As I pointed out above: if I use this if statement instead, it works 100%

if(isset($_GET['subtask'])){

Something turns wrong when using $_POST['task'] in the if statement...
0
 
LVL 61

Accepted Solution

by:
Kevin Cross earned 1800 total points
ID: 24804121
Oh, yeah and you have to ensure that you are passing on the 'subtask' query parameter, either in the post URL or as another value along side task maybe with a hidden variable.

URL method:
<form action="new.php?<?php echo $_SERVER['QUERY_STRING']; ?>" method="post">

Hidden field method:
<input name="subtask" id="subtask" type="hidden" value="<?php echo $_GET['subtask'] ?>" />
(And then change the if to use $_POST['subtask'] instead)
0
Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 
LVL 61

Expert Comment

by:Kevin Cross
ID: 24804148
Remember that the $_POST['task'] is only set after the form has been posted; therefore, you have to test that way.  Otherwise, the IF condition will fail as $_POST['task'] will not be set.
0
 
LVL 27

Assisted Solution

by:Cornelia Yoder
Cornelia Yoder earned 200 total points
ID: 24804471
By the way, NEVER use $_GET or $_POST variables directly in a MySQL query!!   It leaves you wide open to SQL Injection hacking!

Always pass the inputs through a safety function such as mysql_real_escape_string().
0
 
LVL 2

Author Closing Comment

by:AphX
ID: 31601123
Thank you!

Now I see!
0
 
LVL 61

Expert Comment

by:Kevin Cross
ID: 24804556
Great point, yodercm.  Same on me for not mentioning as I presented a security discussion on cross-site scripting (XSS) on the very subject.  Definitely a no no, especially going to a database as it becomes the gift that keeps on giving. ;)
0
 
LVL 61

Expert Comment

by:Kevin Cross
ID: 24804560
*Shame NOT same. :)
0
 
LVL 2

Author Comment

by:AphX
ID: 24805484
Thank you! :)
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Part of the Global Positioning System A geocode (https://developers.google.com/maps/documentation/geocoding/) is the major subset of a GPS coordinate (http://en.wikipedia.org/wiki/Global_Positioning_System), the other parts being the altitude and t…
Originally, this post was published on Monitis Blog, you can check it here . In business circles, we sometimes hear that today is the “age of the customer.” And so it is. Thanks to the enormous advances over the past few years in consumer techno…
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
The viewer will learn how to create a basic form using some HTML5 and PHP for later processing. Set up your basic HTML file. Open your form tag and set the method and action attributes.: (CODE) Set up your first few inputs one for the name and …

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question