PHP filter_input()Functions
Complete PHP Filter Reference Manual
Definition and Usage
The filter_input() function gets input from outside the script (e.g., form input) and filters it.
This function is used to validate variables from non-secure sources, such as user input.
This function can get input from various sources:
- INPUT_GET
- INPUT_POST
- INPUT_COOKIE
- INPUT_ENV
- INPUT_SERVER
- INPUT_SESSION (not yet implemented)
- INPUT_REQUEST (not yet implemented)
If successful, the filtered data is returned. If it fails, FALSE is returned. If the "variable" parameter is not set, NULL is returned.
Syntax
filter_input(input_type, variable, filter, options)
| Parameter | Description |
|---|---|
| input_type | Required. Specifies the input type. See the list above for possible types. |
| variable | Required. Specifies the variable to filter. |
| filter | Optional. Specifies the ID of the filter to use. Default is FILTER_SANITIZE_STRING. SeeComplete PHP Filter Reference Manualfor possible filters. The filter ID can be an ID name (e.g., FILTER_VALIDATE_EMAIL) or an ID number (e.g., 274). |
| options | Optional. Specifies an associative array containing flags/options or a single flag/option. Check each filter for possible flags and options. |
Examples
In this example, we use the filter_input() function to filter a POST variable. The received POST variable is a valid e-mail address:
<?php
if (!filter_input(INPUT_POST, 'email', FILTER_VALIDATE_EMAIL))
{
echo "E-Mail is not valid";
}
else
{
echo "E-Mail is valid";
}
?>
if (!filter_input(INPUT_POST, 'email', FILTER_VALIDATE_EMAIL))
{
echo "E-Mail is not valid";
}
else
{
echo "E-Mail is valid";
}
?>
The output of the code is shown below:
E-Mail is valid
Complete PHP Filter Reference Manual Other Extensions