Re: Battle against the Quotes

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



HtmlEncode the values you trying to display.

Bob Lehmann

"Macsicarr" <nospam@xxxxxxxxxx> wrote in message
news:%2373ZxZ3QFHA.4020@xxxxxxxxxxxxxxxxxxxxxxx
> Hi
>
> Just wanted to see what the standard battle plan is when you want to allow
a
> user to enter a retrieve data from an ASP/DB solution and the infernal
> single or double quote issue comes up if they've been entering these
chars.
>
> For example, I have a web form that is simply:
>
> Name: <standard INPUT text box>
>
> Desc: <standard TEXTAREA>
>
> etc...
>
> End user enters the following into the boxes:
>
> Name: Paul O'Malley
>
> Desc: Paul O'Malley's leg is 3" shorter than it's standard length.
>
> I use the replace command to 'escape' these quotes before I submit them
into
> the Access DB so there is no issue there, but when the user wants to go
into
> the 'Modify Details' form and retrieve these details to mod them its the
> good old HTML that falls foul of the quotes.
>
> Because the VALUE part of the INPUT text box has to be either VALUE="<%the
> name%>" or VALUE='<%the name%>' to encapsulate the data, whichever I
choose
> the end user will always find a way of goofing it up.
>
> For example, if they have typed in 'Paul O'Malley's leg is 3" shorter than
> it's standard' in the Name field and my VALUE used double quotes then all
it
> is going to show is:
>
> Paul O'Malley's leg is 3"
>
> If I use single quotes then all it is going to show is:
>
> Paul O
>
> Do I take it that I should do another replace on the way in so that the
data
> is 'escaped' again before being dropped into the text box? Is there a
> better way?
>
> Thks
>
>
>


.



Relevant Pages

  • Battle against the Quotes
    ... user to enter a retrieve data from an ASP/DB solution and the infernal ... Name: <standard INPUT text box> ... Paul O'Malley's leg is 3" shorter than it's standard length. ... I use the replace command to 'escape' these quotes before I submit them into ...
    (microsoft.public.inetserver.asp.db)
  • Re: LP Standard
    ... A very genuine and real Les Paul can have any kinda truss ... become a Standard if a Standard truss rod cover is put on it, ... know you can replace truss rod covers. ... truss rod covers, you probably wouldn't be so quick to judge a guitar, ...
    (alt.guitar)
  • Re: Questions about Arabic phonology
    ... Paul wrote: ... >> is an emphatic d in modern standard arabic. ... (Badawi level II), and also the colloquials. ...
    (sci.lang)
  • Re: LP Standard
    ... the word Standard had everyone reaching for the definition of a Les Paul. ... Standard truss rod cover is put on it, but the folks in here looking at ...
    (alt.guitar)
  • Re: Media bias in the Israel / Hezbollah conflict
    ... Paul M. Cook wrote: ... I'm sure they can, Marc, but cherry-picking quotes from ... of any religion will do to justify their actions and vilify ... He will not be able to because quotes like that do not exist ...
    (alt.smokers.cigars)