Theory
Portal आख़िरकार सुनता है
अब तक सब कुछ PHP का ख़ुद से बात करना था। अब event portal को LISTEN करना पड़ता है: एक student अपना name और password एक form में type करता है और submit करता है। वह typed data आपके PHP तक कैसे पहुँचता है?
Answer superglobals $_POST और $_GET हैं। और जिस moment real users आपको data भेज सकते हैं, एक hard rule kick in करता है: कभी user input trust मत कीजिए। एक login form exactly वह जगह है जहाँ careless PHP insecure PHP बन जाती है। यह lesson forms को code से जोड़ता है, logic को FUNCTIONS में package करता है, और हर input को validation और sanitization से guard करता है।
Theory
Functions और Scope
एक function reusable logic package करता है:
function lineTotal($price, $qty) { return $price * $qty; }
Parameters data IN carry करते हैं; return एक value वापस भेजता है; parameters के defaults हो सकते हैं ($qty = 1)।
Scope exam-worthy subtlety है: एक function के अंदर variables default से LOCAL होते हैं और बाहर declared variables नहीं देख सकते। एक function automatically एक outer $seats के बारे में नहीं जानता। एक outer (global) variable तक पहुँचने के लिए आपको global keyword या $GLOBALS array इस्तेमाल करना पड़ता है, पर CLEANER तरीका data को एक PARAMETER की तरह पास करना है। Local scope एक feature है: यह functions को self-contained और predictable रखता है।
Theory
$_GET और $_POST: Form के दो Doors
एक HTML form का method decide करता है इसका data कैसे travel करता है:
- GET: data URL query string में जाता है (
portal.php?event=garba), visible और bookmarkable: non-sensitive READS के लिए,$_GETमें आता है - POST: data request BODY में जाता है, URL में नहीं: submissions और sensitive data (जैसे passwords) के लिए,
$_POSTमें आता है
आप एक field को इसके name से पढ़ते हैं: $_POST['username']। यह वही GET-बनाम-POST choice है जिससे आप BCA405-01 के AJAX में मिले थे: reads और bookmarkable data GET इस्तेमाल करते हैं; कोई भी private या state-changing चीज़ (एक login, एक registration) POST इस्तेमाल करती है, क्योंकि आप कभी नहीं चाहते एक password एक URL में बैठे।
Practical
login.php: form, POST, validate, sanitize
<!-- The form: method POST sends data in the body -->
<form method="POST" action="login.php">
<input type="text" name="username">
<input type="password" name="password">
<button type="submit">Log in</button>
</form>
<?php
if ($_SERVER["REQUEST_METHOD"] === "POST") {
// SANITIZE: clean the input
$user = trim($_POST["username"] ?? "");
$user = htmlspecialchars($user); // neutralise HTML/scripts
// VALIDATE: check it is acceptable
if ($user === "") {
echo "Username is required";
} else {
echo "Welcome, " . $user;
}
}
?>
Theory
Validation और Sanitization: कभी Input Trust मत कीजिए
$_GET/$_POST की हर value एक stranger का data है, और blank, malformed, या malicious हो सकती है। दो guards, हमेशा:
- Validation: क्या यह ACCEPTABLE है? Required field present है? क्या यह एक valid email है (
filter_var($e, FILTER_VALIDATE_EMAIL))? Range में एक number? - Sanitization: इसे CLEAN कीजिए।
trim()stray spaces हटाता है;htmlspecialchars()HTML neutralise करता है ताकि कोई<script>inject न कर सके (एक XSS attack); एक sanitize filter वालाfilter_varunwanted characters strip करता है।
Rule absolute है: सारे user input को hostile की तरह treat कीजिए जब तक validate और sanitize न हो जाए। यह skip करना असली sites के hacked होने का तरीका है, और यह security point है जो examiners देखना चाहते हैं।
Quiz
Portal के login को password के लिए GET की बजाय POST क्यों इस्तेमाल करना पड़ता है?
- GET faster है, तो POST सिर्फ़ slow forms के लिए है
- GET data को visible URL में डालता है; एक password को request body (POST) में travel करना पड़ता है, URL, history या logs में नहीं बैठना चाहिए
- POST GET से ज़्यादा fields भेज सकता है
- कोई real difference नहीं है; passwords के लिए दोनों fine हैं
Show the answer
GET data को visible URL में डालता है; एक password को request body (POST) में travel करना पड़ता है, URL, history या logs में नहीं बैठना चाहिए
GET form data को URL की query string में encode करता है, जहाँ यह screen पर visible है, browser history में save होता है, और अक्सर server logs में लिखा जाता है: एक password के लिए catastrophic। POST data को request BODY में डालता है, URL से बाहर, यही वजह है sensitive और state-changing submissions POST इस्तेमाल करती हैं। यह BCA405-01 वाला same GET-बनाम-POST rule mirror करता है। Option A एक speed difference invent करता है। Option C एक real पर secondary point (GET की length limits हैं) state करता है जो security reason नहीं है। Option D dangerously false है: credentials कभी GET के over मत भेजिए। Reads और bookmarks GET इस्तेमाल करते हैं; submissions और secrets POST इस्तेमाल करते हैं।
Think first
Function जो Seats नहीं देख सका
एक student function showSeats() { echo $seats; } लिखता है, $seats = 350 function के OUTSIDE declared है, और यह कुछ नहीं print करता (एक warning के साथ)। क्यों, और clean fix क्या है? फिर tap कीजिए।
Show the answer
PHP variable SCOPE: एक function के अंदर variables LOCAL होते हैं, और एक function automatically इसके बाहर declared variables नहीं देख सकता, तो $seats showSeats() के अंदर undefined है, null और एक warning देते हुए। दो fixes: quick-but-discouraged वाला function के अंदर global $seats; है (या $GLOBALS['seats']); CLEAN वाला इसे PASS करना है: function showSeats($seats) { echo $seats; } और showSeats(350) call कीजिए। Parameters pass करना preferred है क्योंकि यह function को self-contained और predictable रखता है, जबकि globals पर rely करना hidden dependencies create करता है। Local scope आपको protect कर रहा है: यह आपको explicit होने के लिए force करता है कि एक function कौन सा data इस्तेमाल करता है।
Watch out
Function और Form Traps
Globals को Visible मान लेना: function variables local हैं; data parameters की तरह pass कीजिए।
Raw Input Trust करना: इस्तेमाल से पहले हमेशा $_GET/$_POST validate AND sanitize कीजिए।
GET के Over Password: कभी नहीं; credentials और किसी भी state change के लिए POST इस्तेमाल कीजिए।
Missing Key: एक unsubmitted field पर $_POST['x'] warn करता है; safely default करने के लिए $_POST['x'] ?? '' (null coalescing) इस्तेमाल कीजिए।
User Input Raw Echo करना: पहले इसे htmlspecialchars() कीजिए, वरना आप एक XSS hole खोलते हैं।
Theory
Unit 1 Complete: Portal जीवित है
अब आपके पास working Core PHP है: setup, syntax, types, control flow, arrays, functions, और एक real form safely processed। Event portal एक validated user को greet कर सकता है। Unit 2 ADVANCED जाता है: files और uploads handle करना, JSON, cookies और sessions (ताकि एक login pages के across REMEMBERED रहे), email भेजना, और PHP की अपनी object-oriented features exceptions के साथ। Portal memory और structure पाने वाला है।
Summary
Key takeaways
- Functions logic package करते हैं: function name($params){ return $x; }; parameters data in carry करते हैं, return एक value वापस भेजता है।
- Scope: एक function के अंदर variables LOCAL होते हैं; global इस्तेमाल करने की बजाय data parameters की तरह (preferred) pass कीजिए।
- Form data $_GET (URL query string, visible reads) या $_POST (request body, submissions/secrets) में आता है।
- एक field को इसके name से पढ़िए: $_POST['username']; passwords और state changes के लिए POST इस्तेमाल कीजिए, कभी GET नहीं।
- Validation check करता है input acceptable है (required, valid email); sanitization इसे clean करता है (trim, htmlspecialchars, filter_var)।
- कभी user input trust मत कीजिए: injection/XSS रोकने के लिए हर value validate और sanitize कीजिए।
- Memory hook: default से local scope, secrets के लिए POST, और कभी एक stranger का input trust मत कीजिए।