Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Connetu_C

Privileged
  • Joined

  • Last visited

Everything posted by Connetu_C

  1. Seems to be this section causing the problem: <?=$RssLink->item(0)->nodeValue?>" target="_blank"><?=$RssTitle->item(0)->nodeValue?></a></div> <div class="rssdesc"><?=$RssDesc->item(0)->nodeValue?></div> Rather than using object reference operator chaining, you need to use a temporary variable. For example: // Replace this next line: $RssLink->item(0)->nodeValue; // with these two (using an intermediate variable): $tmp = $RssLink->item(0); $tmp->nodeValue; In your case: <?=$RssLink->item(0)->nodeValue?> becomes: <?php $tmp = $RssLink->item(0); echo $tmp->nodeValue ?>
  2. I see now that when you say "constant" you mean one declared using define(). In OO PHP there is a second type which uses the const keyword (more in line with other programming languages like C/C++). There is an example (#1) at PHP: constant in the PHP manual which shows both types. Coming from a background of strongly typed languages, I find PHP peculiar in many ways - and calling the define() syntax a "constant" is one of them. I'll try to explain my comment about this: in most other languages a constant is a "variable which cannot be modified" and exists in the same way as any other variable in the language (in RAM, binaries etc.). But in some languages like C/C++ there is also the concept of a definition using #define (very similar to the PHP syntax) which assigns a value to a named definition, but this definition is substituted before compilation. It isn't the same as a constant and isn't stored in binaries as a variable. In those languages, a constant variable is much preferred over a preprocessor definition (a #define). In OO PHP the same can be said. Using a class constant provides namespace scoping and eliminates the chance of conflicts between identically named constants. It is better to use the const syntax than define() if you're using OOP. This is shown in Example #1 at PHP: Class Constants in the manual.
  3. The purpose of a constant is merely to prevent you accidentally modifying its value in the script. If you attempt to do this, you should get a warning or error. There is no other difference in how they are used, stored in RAM or (in the case of compiled languages) saved in binaries. Generally, constants are preferred over define() preprocessor definitions (which aren't variables in any sense), but proprocessor definitions are still often used.
  4. There are a lot of factors affecting the prices hosting companies can offer. Firstly, the US oversells bandwidth more than the UK does - if everyone actually used all the bandwidth they were promised, most hosting companies (or their IP transit providers, or their upstreams, but ultimately somebody) would go bust. So remember that just because something is offered (as a marketing ploy), it doesn't mean the company will ultimately be able to supply it indefinitely to everybody. Sadly, the main contributing factor is that power costs are higher here for various political reasons. Same as tax on petrol/gasoline. This clearly impacts the cost of running a data centre: server/network power and supporting equipment, cooling and redundancy all add to the overheads. More powerful CPUs, more disks, more redundancy adds to the consumption of each server, so you can see how power costs alone (which keep rising) can cause technology prices to rise. If it were feasible to be more competitive on price, I'm sure most of us would do it. Prices for shared hosting have fallen considerably in the last 10 years and will probably continue to do so, or be replaced by a cheaper next generation of services. Naturally this fall has been mirrored in the USA. Ultimately, the hosting (like everything) is worth what you want to pay for it. For example, is £10/month much if your website is bringing in £300 of revenue a month? Is £150/month for a server excessive if your business is turning over £5k+ monthly? I'd say not, you might disagree. It's all relative, in my opinion. Edit: Note that 1&1 are not UK-based hosts AFAIK (think their servers are in Germany/Netherlands?), and I understand their support staff are offshore too.
  5. Yes, that's exactly it. Note the question didn't ask you to provide confidentiality (encryption). It asked you to ensure the message: originated from the correct server contains data that has not been altered on route by a third party The pre-shared secret key we used does both of these since we assume it is only known by Server A and Server B. If the hash didn't match, one of the assumptions above would be incorrect. If you wanted confidentiality, you could use a symmetric encryption algorithm using the pre-shared key at each end. This is basically what HTTPS does, except SSL also provides it with the way for Server A to generate a new key each time and send it to Server B without it being discovered.
  6. Not quite. Remember I said Server B receives the hashed concatenation of the data and the key. The hash (MD5 or SHA1) part is important - no good just sending the data with a key tacked on the end because... if the key was simply tacked on the end of the message, the key would become very obvious after only two messages had been snooped by an attacker. Example: my key is 123456 and my data is just the word DATA. I want to send the DATA without it being modified en-route. So I get Server A to do this: Append the key (123456) to end of the DATA to give: DATA123456 Calculate the hash of this concatentation, e.g. MD5(DATA123456) = 70cde2d902105dfbb4e8495c28fbb941 Send the DATA and the hash just calculated to the other server, for example as 70cde2d902105dfbb4e8495c28fbb941 DATA Now I have transmitted one hash value (which somewhere contains the shared secret key) and the original DATA. You don't send the key in plaintext, nor do you send a hash of it by itself. Both would be pointless. But a hash of the combined data and the key (simple concatenation suffices) does provide data integrity guarantee. Why? And how can the server at the other end check the integrity of the DATA, since it can't invert the hash function? Think about it.
  7. In the question I read the data is "posted to a different server via a server side post". So I read that as meaning that your form posts to your server first, and it forwards that data to the foreign server via another background HTTP POST. This has to be the case in order for the second server to verify the authenticity of the data - otherwise you have a client who could (and usually will) be absolutely anybody, and this defeats the point of any integrity checks. So we're passing between server A and server B that are both ours and both under our control. As you said, if you do a hash (MD5 or better SHA1) of the data to be transmitted, you'll just get the same result anybody could produce, and it's useless. But, what if both machines store a shared secret key - like a really strong password we have setup on both machines? Then if we have the DATA and the KEY we could send data in the POST body like this: hash(concat(DATA,KEY)) DATA So we've concatenated the DATA with the KEY and produced a hash (MD5 or SHA1 or similar) value. We transmit that across to the second server. Now, how could that second server verify the integrity of the DATA it receives? And how can you ensure a man-in-middle attack is made infeasible? An IP access list allows or denys access by foreign machines based on their IP address. For example, if server A has IP 192.168.0.20 and server B has IP address 192.168.0.21, then server B might be configured to only accept connections from 192.168.0.20 and block all others. Hence only your server A can connect to server B... that is, unless someone spoofs the IP address 192.168.0.20 on their own machine and pretends to be server A, which isn't too hard to do. Hence IP access lists are one form of security, but aren't secure enough alone to rely upon.
  8. You're told you can't use HTTPS and things like IP access lists can be by-passed by spoofing. Also note you're not being asked for data security (encryption), just integrity (data not modified by man-in-middle). I know how I'd accomplish this, but since this is homework assignment or similar I won't tell you the answer. However, hint: shared secret key. And yes, MD5 or SHA1 could be useful in the toolkit too.
  9. How are your paragraphs separated? Newlines, HTML tags? If it's something as simple as that, you might find the MySQL SUBSTRING_INDEX function useful. For example, if you had two newlines (\n\n) separating the paragraphs then: SELECT SUBSTRING_INDEX(textField,'\n\n',1) FROM mytable should return the first paragraph of mytable.textField. I'd need more information on the exact structure of your data in the fields to help further
  10. You should not need to use an AddType line for the .php, certainly not overriding the PHP handler and setting it to a text/x-server-parsed-html (SSI-style) MIME. It should however be sufficient to add index.php to DirectoryIndex, like this: Options +Includes AddType text/x-server-parsed-html .html AddType text/x-server-parsed-html .shtml AddType text/x-server-parsed-html .htm DirectoryIndex index.php index.shtml index.html index.htm Options +ExecCGI AddType application/x-httpd-cgi .cgi AddType application/x-httpd-cgi .pl Note I put index.php before index.shtml - this just means the PHP script will be tried in preference to the .shtml file. But you can reverse those if you wish to give the PHP lower priority. If that doesn't work you could try a .htaccess with a rewrite like this: RewriteEngine on RewriteRule ^$ /index.php [L] Does that work for you?
  11. This most likely isn't a problem with one line of the script. That final line is just the "tipping point" (peak) of the problem. The memory allocation error occurs because the entire script cannot fit inside the default 8MB memory limit. The "quick fix" is to increase the memory limit for your script on the server. The real solution is to find out where the PHP script is requiring nearly 8MB memory and optimise the code better. It's obvious the script is 2000+ lines long, which is very long for an interpreted piece of code. Unless you're caching a lot of data in memory, I really don't see why it should overrun the limit however. You might also find useful links by Googling "PHP Allowed memory size exhausted".
  12. Don't forget that if you do that change, you also need this one: $id = $r["id"]; to $id = $row["id"];
  13. This is probably because you're using $row instead of $r inside the loop in some places! Either change all $r to $row or vice-versa. Does that work now?
  14. Java EE/Web is great when you need a platform with container-managed features like persistence, security and a whole host of APIs and libraries for a wide variety of tasks. It also has performance optimisations out-of-the-box which usually only come with extra setup and/or cost with PHP. Having said that, Java is going to be overkill for the kind of simple CRUD site you require. I'd recommend basing your decision on what hosting platform you want to use: if it's Linux, PHP is going to be easier to manage; if it's Windows, ASP(.NET) is the way to go.
  15. A variable index within an array should pose no problems. One bad thing is that you've used id without either declaring this as a variable $id (if that's what you intended), or surrounding it with quotes as a string 'id' or "id" (which is what I think you meant). The real reason this doesn't work is because you're doing an = and not an == comparison. You should have: if($_POST[$row_services_query["id"]] == "n") {
  16. Yep You're selecting primarily from services, so you'll get one row for each of the rows in that table. The JOIN then asks MySQL to append, for each row in services, the data from a row in table_link_customer_services - specifically, we want the row for which the services.id = table_link_customer_services.services_id. But we also only want to join the row for the record if that link table's row is for the customer we're interested in (rather than any other customers in the link table). Those two conditions are the ON conditions we use to concatenate the results from the two tables. The l.customer_id in the SELECT will then either be the customer_id from the link table (if there was such an entry), or it will be NULL if no matching row existed. The PHP then checks to see if the customer_id was retrieved or not and adds the checked="checked" as appropriate. JOINs are exceedingly useful when merging data from multiple tables. You can read more about MySQL JOINs (and the different types) there.
  17. To reply to myself, an alternative which may give better performance on large datasets is to use a JOIN: $idsession = $_SESSION['id']; $query_list = mysql_query("SELECT v.id,v.name,v.description,l.customer_id FROM services v LEFT JOIN table_link_customer_services l ON (v.id=l.service_id AND l.customer_id=$idsession)"); // and the rest same as I had above Again, untested; let me know if it works for you!
  18. Looks like a very convoluted and inefficient way to do what you want - you can do it all in one SQL query, like this: $idsession = $_SESSION['id']; $query_list = mysql_query("SELECT v.id,v.name,v.description,(SELECT count(*) FROM table_link_customer_services WHERE services_id=v.id AND customer_id=$idsession) FROM services v"); while ($row = mysql_fetch_row($query_list)){ echo $row[1] . "<input type=\"checkbox\" name=\"" . $row[0] . "\" value=\"y\"". ($row[3]>0 ? "checked=\"checked\"" : "") ."/><br />"; } I haven't tested this, it might be buggy. But it's a start. Hope that helps
  19. This is a good point actually, one which I'd overlooked by concentrating too hard on the regex. Using explode() would be easier and give better performance since it doesn't need to compile your pattern and run the regex parser. For example: $url = '/alpha/beta/gamma/delta/epsilon/'; $parts = explode("/",$url); print_r($parts); which outputs: Array ( [0] => [1] => alpha [2] => beta [3] => gamma [4] => delta [5] => epsilon [6] => ) You can obviously remove the empty items (or trim the original / from the front and end of $url) and add the missing slashes if you want.
  20. At first this sounded like a greedy operator problem, but then I tried it and realised it didn't help setting to ungreedy - I don't think the expression is quite correct. I think this is a better solution (which works): $pattern = '!/([^/]+)!'; //$pattern = '!/([-0-9a-z]+)!'; // use this if you want to be specific about allowed characters $url = '/alpha/beta/gamma/delta/epsilon/'; preg_match_all($pattern,$url,$matches); print_r($matches[0]); This then outputs: Array ( [0] => /alpha [1] => /beta [2] => /gamma [3] => /delta [4] => /epsilon ) which I assume is what you wanted?
  21. I would expect one database containing a handful of tables (e.g. "users", "catalogue" and "orders" spring to mind immediately). You'll probably find the number of tables increases as you think more about the database design.
  22. Connetu_C replied to Faevilangel's topic in Server Side
    You're not concatenating the strings properly - you're forgetting to add a . between lines, and you have an extra . before the closing ). You should have either: mail( "info@sglettings.co.uk", "Contact Form Results", "Name:" .$name. "<br />" . "Contact No:" .$phone. "<br />" . "Enquiry:" .$enquiry ); (note the extra . after the "<br />" on each line), or reduce the number of concatenations required with: mail( "info@sglettings.co.uk", "Contact Form Results", "Name:" .$name. "<br />Contact No:" .$phone. "<br />Enquiry:" .$enquiry ); You can also insert variables directly into the strings in PHP, without doing explicit concatenation, like this: mail( "info@sglettings.co.uk", "Contact Form Results", "Name: $name<br />Contact No: $phone<br />Enquiry: $enquiry"); Hope that helps!
  23. Depending on your host/control panel, it should be quite easy. The "virtual host aliases" technique I mention is usually referred to as "domain aliases" or "domain mappings". In Apache, each additional domain can be configured with a ServerAlias line in the site's configuration file. It's as simple as adding those lines to the file and reloading the server. Control panels like Plesk and (I believe) cPanel have this functionality. Ask your host/administrator if you're still unsure.
  24. A search engine robot is more likely to follow the 301 (Permanently Moved) redirect and ignore the original URL because (according to RFC 2616 on HTTP/1.1): For that reason, I'd have thought either virtual host aliases in your server configuration (so all those websites actually are the same thing) or an Apache server with mod_rewrite as a front-end would be preferable (much larger overheads with the latter). Rather than doing a redirect, you could then serve the pages on perfectwedding.com as the same ones as on the bridesmaid.com domain etc., without changing domain. That way they all look like identical sites with no redirects and a search engine is less inclined to drop the domain from its results. But robots are fairly good at spotting these things, so you may find it doesn't help overly much anyway, if the sites have identical content. The only real problem with this approach is that SSL/TLS would fail on all but the domain to which the certificate was assigned - so if you use SSL/TLS anywhere, you'll need to do an actual redirection to the domain shown on the certificate at the point of entering HTTPS, to avoid browser warning messages.
  25. Server SSL/TLS basically provides encryption (so the data you send between client and server cannot be read by anyone), integrity (to ensure data cannot be altered by a man-in-the-middle), and verification of the server's identity to the client. How to configure TLS (the successor to SSL) depends on which server you are using, but it's usually quite simple. You need your own dedicated IP address because TLS operates at the Internet (IP) layer and not the application layer. Then you do this: Generate a private key (typically RSA 1024 bit) Generate a Certificate Signing Request (CSR) Send the CSR to a recognised Certificate Authority (CA) The CA will send you a new certificate back Copy the private key and certificate to a configuration directory of your web server Configure your web server with the paths of the key and certificate That's pretty much it... sounds complicated at first, but it's really not. Knowing how to generate the key and CSR is the hardest part, and many hosting companies will do that for you!

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.