We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 31037
    • 358 Posts
    Soon I’ll be ready to release a beta of my first add-on for MODx, 300 lines of code is not bad for a total newbie! wink

    But now I have this stupid newbie problem, and I’m pretty embarrassed to ask, but if I’m going to get finished I need to cheat by asking for help! smiley

    I need to send parameters from a link to a snippet call, which is placed on another page.

    I have a page which lists some users data from a table. In order for my snippet to know which user to get data for, I need to call my snippet like this:

    [[ppp? &show_Data_For_Id=`#`]] where # should be replaced by id depending on which link in a webuser list I clicked on.

    (This must sound confusing, it’s really hard to explain with my bad English...)

    I’ll try explain another way. I have on a seperate page a list (as links) of users. When someone click on a link they get redirected to the page with my snippet call. I need to send the id of that user to my snippet call (as shown above) on the page which will list the user data (I can include the id in the link as it is available on the page with the user links).

    As you can see I’m pretty confused, can’t even describe what I want to do! But anyway, if someone can give me a tip on a possible solution, or hint where I can see a similar solution in another snippet, it would really make my day!

    I would prefer not to use a form for this if possible.

    Stop laughing and help me now! wink
      • 7923
      • 4,213 Posts
      Do you mean link <a href="mylink.html?show_Data_For_Id=1231">

      and in snippet you do:

      $show_Data_For_Id = $_GET[’show_Data_For_Id’];

      ?


        "He can have a lollipop any time he wants to. That's what it means to be a programmer."
        • 31037
        • 358 Posts
        Hmmm... good question... ok, is it maybe so that I can leave out the &show_Data_For_Id=`#` in my call and access it anyway in my ppp snippet?

        So if I call with only [[ppp]] I’ll still be able to access show_Data_For_Id?

        I’m thinking out loud now, I’ll do some testing instead... could it really be that simple? Hmmm... I’ll be back!

        Thanks! smiley
          • 7923
          • 4,213 Posts
          Yes, if i understood your question fully.. if you just want to access the link query string parameters in a snippet, you do $_GET[’url_param_name’].. that’s basic php. You don’t need to define the url params in snippet call.

          So to be more clearer, if you need to get snippet parameter values, use something like:
          $myParam = (isset($myParam)) ? $myParam : "default value";

          If you need to get url query string parameter values, use:

          $myParam = (isset($_GET[’myParam’])) ? $_GET[’myParam’] : "default value";

          Or if you want that some parameters can be overridden from url, have both and set the later default value to $myParam.


            "He can have a lollipop any time he wants to. That's what it means to be a programmer."
            • 31037
            • 358 Posts
            Thank you!

            Isn’t it strange that sometimes you do some advanced stuff without problems, but then when it comes to an easy newbie thing you are all stuck!

            I just thought I had to pass the parameter to the snippet call first, but of course I can access it with the GET. My problem is that I don’t always understand how things are parsed in MODx. I think I think to much!

            Anyway, your first post solved it for me! smiley And thanks for the extra info in your other post!

            Now I’ll start cleaning up my code, create some documentation and do lots of testing to see if I can post my little add-on in the "Snippets in development" forum in a day or two.

            Thanks again!!! smiley

              • 23491 ☆ A M B ☆
              • 1,056 Posts
              One programmer to another, I’d recommend ensuring that your parameters referenced via _GET/_POST/_REQUEST are properly "cleaned" before passing to the DB/STDOUT.

              In other words, make necessary efforts to curb XSS/SQL-Injection vulnerabilities.

              I’ll keep my eyes open for your add-on! laugh
                Mike Reid - www.pixelchutes.com
                MODx Ambassador / Contributor
                [Module] MultiMedia Manager / [Module] SiteSearch / [Snippet] DocPassword / [Plugin] EditArea / We support FoxyCart
                ________________________________
                Where every pixel matters.
                • 31037
                • 358 Posts
                Thanks for the advise! To be honest I haven’t thought a bit about security when creating this snippet. I’m a total PHP/MySql/MODx newbie, so if I just can get something working I’m happy with that!

                I’m making my add-on to learn php and other stuff, so security and other stuff I hope to get advices on when posting my alpha version in a few days.

                Don’t even know if someone will get any use of my snippet (although I think so) but I’ll sure will use it on my own sites until a pro makes something better wink

                Hopefully my snippet will help at least a few, I would really like my MODx adventures to start with a contribution to the community!
                  • 26435
                  • 1,193 Posts
                  yeah, I agree with pixelchutes.

                  before you save to the db, make sure you run
                  $modx->db->escape($yourvarfromGET);


                  -sD-
                    Husband, Father, Brother, Son, Programmer, Atheist, Nurse, Friend, Lover, Fighter.
                    All of the above... in no specific order.


                    I send pointless little messages
                    • 31037
                    • 358 Posts
                    Oki, I’ll add that before releasing my alpha smiley

                    Thanks both of you!
                      • 28042 ☆ A M B ☆
                      • 24,524 Posts
                      If you are passing a string, you can also run it through a check to make sure nothing illegal got injected, or if it’s supposed to be a number, use is_numeric on it. Then use $modx->db->escape() before adding it to the database!
                        Studying MODX in the desert - http://sottwell.com
                        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                        Join the Slack Community - http://modx.org