[MySqli擴(kuò)展]①③--評(píng)論系統(tǒng)、表單輸入過濾

Paste_Image.png

http://img.mukewang.com/down/55fa763b0001745800000000.rar

index.php

<?php

?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
    <meta http-equiv="Content-Type" content="text/html;charset=UTF-8" />
    <title>Document</title>
    <link rel="stylesheet" type="text/css" href="style/style.css" />
</head>
<body>
<h1>慕課網(wǎng)評(píng)論系統(tǒng)</h1>
<div id='main'>
    <?php
//    foreach($comments as $val){
//        echo $val->output();
//    }
    ?>
    <div id='addCommentContainer'>
        <form id="addCommentForm" method="post" action="">
            <div>
                <label for="username">昵稱</label>
                <input type="text" name="username" id="username" required='required' placeholder='請輸入您的昵稱'/>

                <label for="face">頭像</label>
                <div id='face'>
                    <input type="radio" name="face" checked='checked' value="1" />![](img/1.jpg)   
                    <input type="radio" name="face"  value="2" />![](img/2.jpg)   
                    <input type="radio" name="face"  value="3" />![](img/3.jpg)   
                    <input type="radio" name="face"  value="4" />![](img/4.jpg)   
                    <input type="radio" name="face"  value="5" />![](img/5.jpg)   
                </div>
                <label for="email">郵箱</label>
                <input type="email" name="email" id="email" required='required' placeholder='請輸入合法郵箱'/>

                <label for="url">個(gè)人博客</label>
                <input type="url" name="url" id="url" />

                <label for="content">評(píng)論內(nèi)容</label>
                <textarea name="content" id="content" cols="20" rows="5" required='required' placeholder='請輸入您的評(píng)論...'></textarea>
                <input type="submit" id="submit" value="發(fā)布評(píng)論" />
            </div>
        </form>
    </div>
</div>
<script type="text/javascript" src="script/jquery.min.js"></script>
<script type="text/javascript" src="script/comment.js"></script>
</body>
</html>

doAction.php

<?php
header("Content-type:text/html;charset=utf-8");
require_once 'connect.php';
require_once 'comment.class.php';
?>

connect.php

<?php
$mysqli = new mysqli('localhost', 'root', '', 'imoocComment');
if ($mysqli->errno) {
    die('CONNECT ERROR ' . $mysqli->error);
} else {
    $mysqli->set_charset('UTF8');
}

cpmment.class.php

<?php

class Comment
{
    private $data = array();

    function __construct($data)
    {
        $this->data = $data;
    }

    /**
     * 檢測用戶輸入的數(shù)據(jù)
     * @param $arr
     * @return bool
     */
    public static function validate(&$arr)
    {
        if (!(filter_input(INPUT_POST, 'email', FILTER_VALIDATE_EMAIL))) {
            $errors['email'] = '請輸入合法郵箱';
        }
        if (!(filter_input(INPUT_POST, 'url', FILTER_VALIDATE_URL))) {
            $url = "";
        }
        if (!(filter_input(INPUT_POST, 'content', FILTER_CALLBACK, array('options' => 'Comment::validate_str')))) {
            $errors['content'] = "請輸入合法內(nèi)容";
        }
        if (!(filter_input(INPUT_POST, 'username', FILTER_CALLBACK, array('options' => 'Comment::validate_str')))) {
            $errors['username'] = "請輸入合法用戶名";
        }
        $options = array(
            'min_range' => 1,
            'max_range' => 5
        );
        if (!(filter_input(INPUT_POST, 'face', FILTER_VALIDATE_INT, $options))) {
            $errors['face'] = "請輸入合法頭像";
        }
        if (!empty($errors)) {
            $arr = $errors;
            return false;
        }
        $arr = $data;
        $arr['email'] = strtolower(trim($arr['email']));
        return true;

    }

    /**
     * 過濾用戶輸入的特殊字符
     * @param $str
     * @return bool|string
     */
    public static function validate_str($str)
    {
        if (mb_strlen($str, 'UTF8') < 1) {
            return false;
        }
        //nl2br 將\n轉(zhuǎn)換成br
        //htmlspecialchars 把一些預(yù)定義的字符轉(zhuǎn)換為 HTML 實(shí)體
        //ENT_QUOTES單引號(hào)也轉(zhuǎn)義
        $str = nl2br(htmlspecialchars($str, ENT_QUOTES));
        return $str;

    }
}
最后編輯于
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請聯(lián)系作者
平臺(tái)聲明:文章內(nèi)容(如有圖片或視頻亦包括在內(nèi))由作者上傳并發(fā)布,文章內(nèi)容僅代表作者本人觀點(diǎn),簡書系信息發(fā)布平臺(tái),僅提供信息存儲(chǔ)服務(wù)。

推薦閱讀更多精彩內(nèi)容