
Jasmine
Administrator
Apr 26, 2001, 9:09 AM
Post #5 of 5
(600 views)
|
Both of the above will work on the form display end (one assuming js is enabled), but neither will stop someone from saving the form locally, stripping the limitations, and entering a thousand characters. Two suggestions: 1) Make sure you check the referrer of the form submission. If it's not from your domain, then don't accept it. 2) Check and/or shorten the string at the form processing end.
if ( length $message > 160 ){ my $trunc = substr( $message, 0, 160 ); print <<EOF; Your input is too long and has been truncated to : $trunc If you don't like it, try again. EOF }
|