Re: Wildcards for 4GL pgm
Posted in 1996
Billy Wheeler wrote: > > At 09:18 PM 5/15/96 -0500, Cheryl Kendricks wrote: > >I'm doing this for one of my Pgm/Analyst: > >How do you get around wildcard characters in a form using query by example > >for security measures? > > Don't use CONSTRUCT? Not quite as facetous as Billy might have meant it. If the users are only allowed to input specific query criteria, and you don't want them to put in any of the "special" CONSTRUCT features (wildcards like *, ?, [], the : range operator for dates and numbers, or any of the <, >, !=, equality operators), just use an INPUT statement and build your own where clause from the input. > > Or, use the AFTER FIELD in the CONSTRUCT to scan through the user criteria > and check for wildcards. This could work too, versions 4.10 and above. Specifically: AFTER FIELD char_column LET charstring = get_fldbuf(char_column) IF charstring MATCHES "*[*?\\[]*" THEN ERROR "Wildcards not allowed" DISPLAY "" TO screen_form.char_column NEXT FIELD char_column END IF (caveat: I tried IF charstring MATCHES "*\\**", but the backslash didn't work to treat the wildcard literaly; entering a non-wildcard character caused the MATCH to return TRUE) A similar thing would work for DATE and numeric fields; remembering that get_fldbuf() returns a CHAR always. Another approach would be to test the character string CONSTRUCT fills for the word "matches", which I think will only occur in the string if at least one wildcard is used. This wasn't exhaustively tested: WHILE TRUE CONSTRUCT ... filter_clause ON .... ... END CONSTRUCT IF NOT int_flag AND filter_clause MATCHES "*matches*" THEN ERROR "Please remove wildcard input" CONTINUE WHILE END IF EXIT WHILE END WHILE I *did* try to put the test in an AFTER CONSTRUCT control block instead of putting the whole CONSTRUCT in a WHILE loop, but I learned something new about CONSTRUCT; the filter_clause character string was still NULL in AFTER CONSTRUCT. //////////////// ======================================================= ////////// // Dennis J. Pimple Informix Software, Inc. ////// / /// Principal Consultant 5299 DTC Blvd Suite 740 ///// // //// dennisp@informix.com Englewood CO 80111 //// // ///// /// // ////// recept: 303-850-0210 // // /////// direct: 303-740-5611 Opinions expressed are mine, / /////////// fax: 303-843-6408 and do not necessarily //////////////// http://www.informix.com reflect those of my employer