PHP filter_input()Functions


PHP Filter 参考手册Complete PHP Filter Reference Manual

Definition and Usage

The filter_input() function gets input from outside the script (e.g., form input) and filters it.

This function is used to validate variables from non-secure sources, such as user input.

This function can get input from various sources:

  • INPUT_GET
  • INPUT_POST
  • INPUT_COOKIE
  • INPUT_ENV
  • INPUT_SERVER
  • INPUT_SESSION (not yet implemented)
  • INPUT_REQUEST (not yet implemented)

If successful, the filtered data is returned. If it fails, FALSE is returned. If the "variable" parameter is not set, NULL is returned.

Syntax

filter_input(input_type, variable, filter, options)

Parameter Description
input_type Required. Specifies the input type. See the list above for possible types.
variable Required. Specifies the variable to filter.
filter Optional. Specifies the ID of the filter to use. Default is FILTER_SANITIZE_STRING. SeeComplete PHP Filter Reference Manualfor possible filters.

The filter ID can be an ID name (e.g., FILTER_VALIDATE_EMAIL) or an ID number (e.g., 274).

options Optional. Specifies an associative array containing flags/options or a single flag/option. Check each filter for possible flags and options.


Examples

In this example, we use the filter_input() function to filter a POST variable. The received POST variable is a valid e-mail address:

<?php
if (!filter_input(INPUT_POST, 'email', FILTER_VALIDATE_EMAIL))
{
echo "E-Mail is not valid";
}
else
{
echo "E-Mail is valid";
}
?>

The output of the code is shown below:

E-Mail is valid


PHP Filter 参考手册Complete PHP Filter Reference Manual Other Extensions