[ * // Placeholder text * 'e.g., jsmith', * * // Validation requirements * [ * 'no_spaces', * 'checkSQL', * ], * ], * ]; * * EXAMPLE CLIENT IMPLEMENTATION * * function validate($standard_fields, $admin_fields) { * include('includes/input_validation.php'); * $error = ''; * foreach($standard_fields as $field => $arr) { * // Get the requirements from the associative array. * $validationRequirements = $arr[1]; * * foreach($validationRequirements as $validReq) { * switch($validReq) { * case 'no_spaces': * if(no_spaces($_POST[$field])) { * $error .= '
' . $field . ' does not allow spaces.
'; * } * break; * default: * $error .= 'Something went wrong...
'; * break; * } * } * } * } */ function no_spaces($input) { return !str_contains($input, ' '); } function no_digits($input) { for ($i = 0; $i < strlen($input); $i++) if (is_numeric($input[$i])) return false; return true; } function no_backslash($input) { for ($i = 0; $i < strlen($input); $i++) if ($input[$i] === '\\') return false; return true; } /* * This checks for the following characters: * ' ' ! " # $ % & ' ( ) * + , - . / : ; < = > ? @ [ * \ ] ^ _ ` { | } ~ * * TODO: Add support for additional special characters available through * other means. */ function no_special($input) { $special = [ '!', '"', '#', '$', '%', '&', "'", '(', ')', '*', '+', ',', '-', '.', '/', ':', ';', '<', '=', '>', '?', '@', '[', '\\', ']', '^', '_', '`', '{', '|', '}', '~', ]; for ($i = 0; $i < strlen($input); $i++) if (in_array($input[$i], $special)) return false; return true; } function only_digits($input) { for ($i = 0; $i < strlen($input); $i++) if (!is_numeric($input[$i])) return false; return true; } function only_digits_x($input, $x) { if (strlen($input) != $x) return false; for ($i = 0; $i < strlen($input); $i++) if (!is_numeric($input[$i])) return false; return true; } function only_letters($input) { return (preg_match('/[^A-Za-z]*/', $input) == 1 ? true : false); } function only_letters_x($input, $x) { if (strlen($input) != $x) return false; return (preg_match('/[^A-Za-z]*/', $input) ? true : false); } // TODO: Add additional step which tests if the email exists. function valid_email($input) { if (!str_contains($input, '@')) return false; $email = explode('@', $input); if (count($email) != 2) return false; return true; } /* * Note: While this function handles the most common variations of a phone * number (and potential missed or inconsistent entry), it does not apply * any formatting. The client must handle data consistency themselves. */ function valid_phone($input) { $formats = [ '/^\d{10}$/', // xxxxxxxxxx '/^\d{3}-\d{7}$/', // xxx-xxxxxxx '/^\d{6}-\d{4}$/', // xxxxxx-xxxx '/^\d{3}-\d{3}-\d{4}$/', // xxx-xxx-xxxx '/^\(\d{3}\)\d{7}$/', // (xxx)xxxxxxx '/^\(\d{3}\)\d{3}-\d{4}$/', // (xxx)xxx-xxxx '/^\(\d{3}\) \d{3}-\d{4}$/', // (xxx) xxx-xxxx '/^\(\d{3}\)\d{3} -\d{4}$/', // (xxx)xxx -xxxx '/^\(\d{3}\)\d{3}- \d{4}$/', // (xxx)xxx- xxxx '/^\(\d{3}\)\d{3} - \d{4}$/', // (xxx)xxx - xxxx '/^\(\d{3}\) \d{3} -\d{4}$/', // (xxx) xxx -xxxx '/^\(\d{3}\) \d{3}- \d{4}$/', // (xxx) xxx- xxxx '/^\(\d{3}\) \d{3} - \d{4}$/', // (xxx) xxx - xxxx '/^\d{3} \d{7}$/', // xxx xxxxxxx '/^\d{6} \d{4}$/', // xxxxxx xxxx '/^\d{3} \d{3} \d{4}$/', // xxx xxx xxxx '/^\d{3} \d{3}-\d{4}$/', // xxx xxx-xxxx '/^\d{3}-\d{3} \d{4}$/', // xxx-xxx xxxx '/^\d{3}\.\d{7}$/', // xxx.xxxxxxx '/^\d{6}\.\d{4}$/', // xxxxxx.xxxx '/^\d{3}\.\d{3}\.\d{4}$/', // xxx.xxx.xxxx ]; foreach ($formats as $regex) if (preg_match($regex, $input)) return true; return false; } /* * TODO: This should ensure the user's password consists of the following: * - length > 8, * - 1+ uppercase letters, * - 1+ lowercase letters, * - 1+ digits, * - 1+ special characters */ function pw_strength($input) { return true; } /* * TODO: Need to implement SQL Injection prevention. * * Note: This should have the additional step of blacklisting a user who * attempts SQL Injection. At least adding any valid submitted information * to a DB table in case they attempt to create a 'valid' account, or * flagging a 'valid' account that attempts SQL Injection. This will require * a lot of research and therefore time. For now, since this isn't public * facing, I'll operate with some trust in the user. * * Also, this might be better in a database functions file instead. */ function check_sql($input) { return false; }