We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 15716
    • 57 Posts
    OK, I’m not good with PHP...so this problem might be an easy fix.

    The problem is: I am working with eForm2db and I want the user to be able to enter an apostrophe in their name (i.e. "O’Brien") without throwing a parse error. I’m know the problem is when it is trying to write to the DB, but I have no clue on how to fix it...

    Any ideas or solutions?

    Cheers!
      • 30223
      • 1,010 Posts
      You should really ask this question in the eform2db thread. As far as I know an apostrophe (or single quote) shouldn’t give you any hassle in eForm itself and in eform2db you need to make sure you properly escape the input. You can use $modx->db->escape() for that.
        • 25124
        • 54 Posts
        Hi Toby,

        Can you explain where I need to add this?

        $modx->db->escape()



        A single apostrophe breaks the email2db for me sad

        I’m thinking somewhere in the eForm2db snippet
         <?php
        function getServer( &$fields ){
        // remote_addr
        $fields['remote_addr']=$_SERVER['REMOTE_ADDR'];
        $fields['remote_host']=$_SERVER['REMOTE_HOST'];
        $fields['user_agent']=$_SERVER['HTTP_USER_AGENT'];
        //return success
        return true;
        }
        
        function eForm2db( &$fields )
        	{
        		global $modx;
        		// Init our array
        escape
        		$dbTable = array();
        		$dbTable[Title] = $fields[Title];
        		$dbTable[Name] = $fields[Name];
        		$dbTable[Company] = $fields[Company];
        		$dbTable[Address] = $fields[Address];
        		$dbTable[Telephone] = $fields[Telephone];
        		$dbTable[Fax] = $fields[Fax];
        		$dbTable[email] = $fields[email];
        		$dbTable[Quantity] = $fields[Quantity];
        		$dbTable[DesignContent] = $fields[DesignContent];
        		$dbTable[Request] = $fields[Request];
        		$dbTable[IP] = $_SERVER['REMOTE_ADDR'];
        		$dbTable[Host] = $_SERVER['REMOTE_HOST'];
        		$dbTable[Agent] = $_SERVER['HTTP_USER_AGENT'];
        		// Run the db insert query
        		$dbQuery = $modx->db->insert($dbTable, 'aafeedback' );
        		return true;
        	}
        ?>
          • 30223
          • 1,010 Posts
          You should escape all values from your form before saving them in a database like this:

          
          $dbTable['Name'] = $modx->db->escape($fields['Name']);
          
          

          You should also quote the array indexes! [’Name’] instead of [Name]!
            • 25124
            • 54 Posts
            Toby, I now have everything working. grin

            I started with modX I week ago today and I must say how impressed I am with the level of service I’ve got off you guys - it feels like a really good community. I’m not an expert in programming by any means of the word but everyones help here has not gone missed. I will be making a nice donation as a thanks for all the hard work.

            Regards
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              In fact, you should get in the habit of doing that with all user input, as it helps a bit to prevent security breaches.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org