Alex Lord
Alex Lord
Im using php but i have a problem, when allowing user to create a list they adding charaters they shouldnt, here is a list i collected below

. ; / ? ! " @ $ ()

how can i make sure non of these enter the database in one go instead of mutiple find and replaces ?
Daniel PineaultPresident / Owner CARDA Consultants Inc.
You can use preg_match() to detect them.  

What about using Javascript/JQuery on your page to block the characters in the first place?  See:


@Daniel Pineault would that be the best practice to use ?
First line of defense would be to control the entry on the page itself, then in PHP validate things.

str_replace() can accept an array so you should still be able to perform all you replacements with one line, so something like the following should work:
$string = str_replace(str_split('.;/?!"@$()'), '', $string)

You don't give too many details on the data itself, but perhaps, you may wish to look over Sanitize filters they can also be useful.
nociSoftware Engineer
Bottom line: if you want to hetlp the use jquery etc. may help.
You will still need to strip the special characters if your API forbids them....
(Any API should enforce these checks on things it (dis)allows).

I would not rely on jQuery as it can be bypassed by user /  browser instead make sure you are using server side validation.
This will make sure it's will not save it.

I would not replaced it on the spot, it is better to inform user during the server side validation that those characters are not allowed.
You can also add a small text line under the field to inform what is not allowed to the user


thank you for the help this is just a basic input that i dont want special charaters to be passed into the backend

