Functions and form handling: user-defined functions; parameters and return values; variable scope (global vs. local); handling forms with $_GET and $_POST; basic input validation and sanitization

Functions logic package करते हैं, scope इनके variables को private रखता है, और $_POST/$_GET एक form के data को PHP में carry करते हैं: validation और sanitization हर input पर non-negotiable guard हैं।

12 min read · 10 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

Portal आख़िरकार सुनता है

अब तक सब कुछ PHP का ख़ुद से बात करना था। अब event portal को LISTEN करना पड़ता है: एक student अपना name और password एक form में type करता है और submit करता है। वह typed data आपके PHP तक कैसे पहुँचता है?

Answer superglobals $_POST और $_GET हैं। और जिस moment real users आपको data भेज सकते हैं, एक hard rule kick in करता है: कभी user input trust मत कीजिए। एक login form exactly वह जगह है जहाँ careless PHP insecure PHP बन जाती है। यह lesson forms को code से जोड़ता है, logic को FUNCTIONS में package करता है, और हर input को validation और sanitization से guard करता है।

Theory

Functions और Scope

एक function reusable logic package करता है:

function lineTotal($price, $qty) { return $price * $qty; }

Parameters data IN carry करते हैं; return एक value वापस भेजता है; parameters के defaults हो सकते हैं ($qty = 1)।

Scope exam-worthy subtlety है: एक function के अंदर variables default से LOCAL होते हैं और बाहर declared variables नहीं देख सकते। एक function automatically एक outer $seats के बारे में नहीं जानता। एक outer (global) variable तक पहुँचने के लिए आपको global keyword या $GLOBALS array इस्तेमाल करना पड़ता है, पर CLEANER तरीका data को एक PARAMETER की तरह पास करना है। Local scope एक feature है: यह functions को self-contained और predictable रखता है।

Theory

$_GET और $_POST: Form के दो Doors

एक HTML form का method decide करता है इसका data कैसे travel करता है:

  • GET: data URL query string में जाता है (portal.php?event=garba), visible और bookmarkable: non-sensitive READS के लिए, $_GET में आता है
  • POST: data request BODY में जाता है, URL में नहीं: submissions और sensitive data (जैसे passwords) के लिए, $_POST में आता है

आप एक field को इसके name से पढ़ते हैं: $_POST['username']। यह वही GET-बनाम-POST choice है जिससे आप BCA405-01 के AJAX में मिले थे: reads और bookmarkable data GET इस्तेमाल करते हैं; कोई भी private या state-changing चीज़ (एक login, एक registration) POST इस्तेमाल करती है, क्योंकि आप कभी नहीं चाहते एक password एक URL में बैठे।

Practical

login.php: form, POST, validate, sanitize

<!-- The form: method POST sends data in the body -->
<form method="POST" action="login.php">
  <input type="text" name="username">
  <input type="password" name="password">
  <button type="submit">Log in</button>
</form>

<?php
  if ($_SERVER["REQUEST_METHOD"] === "POST") {
    // SANITIZE: clean the input
    $user = trim($_POST["username"] ?? "");
    $user = htmlspecialchars($user);   // neutralise HTML/scripts

    // VALIDATE: check it is acceptable
    if ($user === "") {
      echo "Username is required";
    } else {
      echo "Welcome, " . $user;
    }
  }
?>

Theory

Validation और Sanitization: कभी Input Trust मत कीजिए

$_GET/$_POST की हर value एक stranger का data है, और blank, malformed, या malicious हो सकती है। दो guards, हमेशा:

  • Validation: क्या यह ACCEPTABLE है? Required field present है? क्या यह एक valid email है (filter_var($e, FILTER_VALIDATE_EMAIL))? Range में एक number?
  • Sanitization: इसे CLEAN कीजिए। trim() stray spaces हटाता है; htmlspecialchars() HTML neutralise करता है ताकि कोई <script> inject न कर सके (एक XSS attack); एक sanitize filter वाला filter_var unwanted characters strip करता है।

Rule absolute है: सारे user input को hostile की तरह treat कीजिए जब तक validate और sanitize न हो जाए। यह skip करना असली sites के hacked होने का तरीका है, और यह security point है जो examiners देखना चाहते हैं।

Quiz

Portal के login को password के लिए GET की बजाय POST क्यों इस्तेमाल करना पड़ता है?

  1. GET faster है, तो POST सिर्फ़ slow forms के लिए है
  2. GET data को visible URL में डालता है; एक password को request body (POST) में travel करना पड़ता है, URL, history या logs में नहीं बैठना चाहिए
  3. POST GET से ज़्यादा fields भेज सकता है
  4. कोई real difference नहीं है; passwords के लिए दोनों fine हैं
Show the answer

GET data को visible URL में डालता है; एक password को request body (POST) में travel करना पड़ता है, URL, history या logs में नहीं बैठना चाहिए

GET form data को URL की query string में encode करता है, जहाँ यह screen पर visible है, browser history में save होता है, और अक्सर server logs में लिखा जाता है: एक password के लिए catastrophic। POST data को request BODY में डालता है, URL से बाहर, यही वजह है sensitive और state-changing submissions POST इस्तेमाल करती हैं। यह BCA405-01 वाला same GET-बनाम-POST rule mirror करता है। Option A एक speed difference invent करता है। Option C एक real पर secondary point (GET की length limits हैं) state करता है जो security reason नहीं है। Option D dangerously false है: credentials कभी GET के over मत भेजिए। Reads और bookmarks GET इस्तेमाल करते हैं; submissions और secrets POST इस्तेमाल करते हैं।

Think first

Function जो Seats नहीं देख सका

एक student function showSeats() { echo $seats; } लिखता है, $seats = 350 function के OUTSIDE declared है, और यह कुछ नहीं print करता (एक warning के साथ)। क्यों, और clean fix क्या है? फिर tap कीजिए।

Show the answer

PHP variable SCOPE: एक function के अंदर variables LOCAL होते हैं, और एक function automatically इसके बाहर declared variables नहीं देख सकता, तो $seats showSeats() के अंदर undefined है, null और एक warning देते हुए। दो fixes: quick-but-discouraged वाला function के अंदर global $seats; है (या $GLOBALS['seats']); CLEAN वाला इसे PASS करना है: function showSeats($seats) { echo $seats; } और showSeats(350) call कीजिए। Parameters pass करना preferred है क्योंकि यह function को self-contained और predictable रखता है, जबकि globals पर rely करना hidden dependencies create करता है। Local scope आपको protect कर रहा है: यह आपको explicit होने के लिए force करता है कि एक function कौन सा data इस्तेमाल करता है।

Watch out

Function और Form Traps

Globals को Visible मान लेना: function variables local हैं; data parameters की तरह pass कीजिए।

Raw Input Trust करना: इस्तेमाल से पहले हमेशा $_GET/$_POST validate AND sanitize कीजिए।

GET के Over Password: कभी नहीं; credentials और किसी भी state change के लिए POST इस्तेमाल कीजिए।

Missing Key: एक unsubmitted field पर $_POST['x'] warn करता है; safely default करने के लिए $_POST['x'] ?? '' (null coalescing) इस्तेमाल कीजिए।

User Input Raw Echo करना: पहले इसे htmlspecialchars() कीजिए, वरना आप एक XSS hole खोलते हैं।

Theory

Unit 1 Complete: Portal जीवित है

अब आपके पास working Core PHP है: setup, syntax, types, control flow, arrays, functions, और एक real form safely processed। Event portal एक validated user को greet कर सकता है। Unit 2 ADVANCED जाता है: files और uploads handle करना, JSON, cookies और sessions (ताकि एक login pages के across REMEMBERED रहे), email भेजना, और PHP की अपनी object-oriented features exceptions के साथ। Portal memory और structure पाने वाला है।

Summary

Key takeaways

  • Functions logic package करते हैं: function name($params){ return $x; }; parameters data in carry करते हैं, return एक value वापस भेजता है।
  • Scope: एक function के अंदर variables LOCAL होते हैं; global इस्तेमाल करने की बजाय data parameters की तरह (preferred) pass कीजिए।
  • Form data $_GET (URL query string, visible reads) या $_POST (request body, submissions/secrets) में आता है।
  • एक field को इसके name से पढ़िए: $_POST['username']; passwords और state changes के लिए POST इस्तेमाल कीजिए, कभी GET नहीं।
  • Validation check करता है input acceptable है (required, valid email); sanitization इसे clean करता है (trim, htmlspecialchars, filter_var)।
  • कभी user input trust मत कीजिए: injection/XSS रोकने के लिए हर value validate और sanitize कीजिए।
  • Memory hook: default से local scope, secrets के लिए POST, और कभी एक stranger का input trust मत कीजिए।

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from Core PHP Programming

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

Functions and form handling: user-defined functions; parameters and return values; variable scope (global vs. local); handling forms with $_GET and $_POST; basic input validation and sanitization · Web Framework and Services (Major-12) · Gri-Learn