in reply to (dkubb) Re: (2) A Little review for a little DBI and CGI?
in thread A Little review for a little DBI and CGI?
I've got taint checking on now, and I use $q=CGI->new. Eventually, I want to write a function that dies gracefully, printing an error to the web browser before it dies. I don't think I want to use CGI::Carp "fatalsToBrowser" as that gives too much information to the nasty people that might be using the stuff. I've changed the sql statement and untainted $criteria, so it has to be only letters and numbers. It was a bit of a pain getting the place holder to work, but eventually...
I don't take such a long critique personally. I'm quite happy to recieve positive and constructive comments. Thank you again.
Unfortunatly, now that it's working so well, I've discovered a bug and need some help. The data is comming from a paradox database. Paradox is able to export it to CSV but isn't smart enough to escape the quote in the titles. I've been looking for a regex on the monastery to add escapes, but haven't found one yet. Do you have any suggestions?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
(tye)Re3: A Little review for a little DBI and CGI?
by tye (Sage) on Mar 28, 2001 at 23:01 UTC | |
by coolmichael (Deacon) on Mar 29, 2001 at 00:45 UTC | |
|
Re: Re: (dkubb) Re: (2) A Little review for a little DBI and CGI?
by marius (Hermit) on Mar 28, 2001 at 22:00 UTC |