PHP Forms and User Input


The $_GET and $_POST variables in PHP are used to retrieve information from forms, such as user input.


PHP Form Handling

One important thing worth noting is that when handling HTML forms, PHP can automatically make the form elements from an HTML page available to PHP scripts.

Example

The following example contains an HTML form with two input boxes and a submit button.

form.html file code:

<html> <head> <meta charset="utf-8"> <title>Example Tutorial (example.com)</title> </head> <body> <form action="welcome.php" method="post">Name:<input type="text" name="fname">Age:<input type="text" name="age"> <input type="submit" value="Submit"> </form> </body> </html>

When the user fills out the form above and clicks the submit button, the form data will be sent to the PHP file named "welcome.php":

welcome.php file code:

Welcome<?php echo $_POST["fname"]; ?>!<br>Your age is<?php echo $_POST["age"]; ?>years old.

The demo accessed through a browser is as follows:

We will explain the $_GET and $_POST variables in PHP in the next chapter.


PHP Getting Dropdown Menu Data

PHP Dropdown Menu (Single Selection)

In the following example, we set three options for the dropdown menu. The form uses the GET method to obtain data. An empty action attribute value means submitting to the current script. We can obtain the dropdown menu value through the name attribute of the select element:

php_form_select.php file code:

<?php $q = isset($_GET['q'])? htmlspecialchars($_GET['q']) : ''; if($q) { if($q =='EXAMPLE') { echo 'Example Tutorial<br>http://www.example.com'; } else if($q =='GOOGLE') { echo 'Google Search<br>http://www.google.com'; } else if($q =='TAOBAO') { echo 'Taobao<br>http://www.taobao.com'; } } else { ?>
<form action="" method="get"> <select name="q"> <option value="">Choose a site:</option> <option value="EXAMPLE">Example</option> <option value="GOOGLE">Google</option> <option value="TAOBAO">Taobao</option> </select> <input type="submit" value="Submit"> </form>
<?php } ?>

PHP Dropdown Menu (Multiple Selection)

If the dropdown menu is multi-select (multiple="multiple"), we can set the selectname="q[]"to obtain values as an array. The following uses the POST method to submit, and the code is as follows:

php_form_select_mul.php file code:

<?php $q = isset($_POST['q'])? $_POST['q'] : ''; if(is_array($q)) { $sites = array( 'EXAMPLE' => 'Example Tutorial: http://www.example.com', 'GOOGLE' => 'Google Search: http://www.google.com', 'TAOBAO' => 'Taobao: http://www.taobao.com', ); foreach($q as $val) { //PHP_EOL is a constant used for line breaks echo $sites[$val] . PHP_EOL; } } else { ?>
<form action="" method="post"> <select multiple="multiple" name="q[]"> <option value="">Choose a site:</option> <option value="EXAMPLE">Example</option> <option value="GOOGLE">Google</option> <option value="TAOBAO">Taobao</option> </select> <input type="submit" value="Submit"> </form>
<?php } ?>

Radio Button Form

In PHP radio button forms, the values of the name attribute are the same, while the value attributes are different. The code is as follows:

php_form_radio.php file code:

<?php $q = isset($_GET['q'])? htmlspecialchars($_GET['q']) : ''; if($q) { if($q =='EXAMPLE') { echo 'Example Tutorial<br>http://www.example.com'; } else if($q =='GOOGLE') { echo 'Google Search<br>http://www.google.com'; } else if($q =='TAOBAO') { echo 'Taobao<br>http://www.taobao.com'; } } else {
?><form action="" method="get"> <input type="radio" name="q" value="EXAMPLE" />Example <input type="radio" name="q" value="GOOGLE" />Google <input type="radio" name="q" value="TAOBAO" />Taobao <input type="submit" value="Submit"> </form>
<?php } ?>

Checkbox

PHP checkboxes can select multiple values:

php_form_select_checkbox.php file code:

<?php $q = isset($_POST['q'])? $_POST['q'] : ''; if(is_array($q)) { $sites = array( 'EXAMPLE' => 'Example Tutorial: http://www.example.com', 'GOOGLE' => 'Google Search: http://www.google.com', 'TAOBAO' => 'Taobao: http://www.taobao.com', ); foreach($q as $val) { //PHP_EOL is a constant used for line breaks echo $sites[$val] . PHP_EOL; } } else {
?><form action="" method="post"> <input type="checkbox" name="q[]" value="EXAMPLE"> Example<br> <input type="checkbox" name="q[]" value="GOOGLE"> Google<br> <input type="checkbox" name="q[]" value="TAOBAO"> Taobao<br> <input type="submit" value="Submit"> </form>
<?php } ?>

Form Validation

We should validate user input as much as possible (through client-side scripts). Browser validation is faster and can reduce the load on the server.

If user input needs to be inserted into the database, you should consider using server-side validation. A good way to validate forms on the server is to send the form data to the current page (asynchronous submission is even better) rather than redirecting to a different page. This way, users can get error messages on the same form page, making it easier for them to spot errors.

Other Extensions