Welcome to FrostSW!

FrostMVC PHP Framework

Documentation   |   Version

Form

FrostMVC\Form

use FrostMVC\Form;

Input sanitisation, HTTP input helpers, and form rendering utilities.

All public methods are static. The primary entry points are:

  • fip() / fig() / val() — read and sanitise POST / GET values.
  • sanitise() — sanitise an arbitrary value.
  • start() / end() — render a <form> element with CSRF token injection.
  • files() — access $_FILES entries.
  • jsonEncode() — JSON-encode a value and mark it safe for Model::escape() contexts.

Methods

::desanitise()

Reverses htmlspecialchars() encoding, restoring HTML entities to their original characters.

::end()

Renders a closing </form> tag.

::fic()

Reads and sanitises a value from $_COOKIE (INPUT_COOKIE).

::fie()

Reads and sanitises a value from $_ENV (INPUT_ENV).

::fig()

Reads and sanitises a value from $_GET (INPUT_GET).

::files()

Returns a $_FILES entry as an object, or all entries as an array. When the requested key is absent, returns an object with error set to UPLOAD_ERR_NO_FILE (4).

::fip()

Reads and sanitises a value from $_POST (INPUT_POST).

::fis()

Reads and sanitises a value from $_SERVER (INPUT_SERVER).

::jsonEncode()

JSON-encodes a value and prepares it to be stored as a string column via the Model.

::pass() —
::pr()

Prints a string with HTML tags stripped and newlines converted to <br/> tags.

::sanitise()

Sanitises a value, protecting against XSS and injection.

::sanitiseObject()

Sanitises a single value, handling objects by casting them to arrays first. Delegates to sanitise() for all actual sanitisation logic.

::start()

Renders an opening <form> tag with the given method, action, and optional extra attributes. When Security::$CSRFTokenConfig is enabled and the method is POST, hidden CSRF token fields are automatically injected.

::val()

Reads from $_GET first; falls back to $_POST when the GET value is absent or null. Useful for endpoints that accept both forms of input.

desanitise() static

Form::desanitise($string)

Reverses htmlspecialchars() encoding, restoring HTML entities to their original characters.

Parameters

$string string

The encoded string.

Returns

string

end() static

Form::end()

Renders a closing </form> tag.

fic() static

Form::fic($name = '', $filter = false, $filter_flag = 0)

Reads and sanitises a value from $_COOKIE (INPUT_COOKIE).

Parameters

$name string

The $_COOKIE key.

Default: ''
$filter int

filter_var() constant. Defaults to FILTER_DEFAULT.

Default: false
$filter_flag int|array

Additional filter_var() flag(s).

Default: 0

Returns

mixed

fie() static

Form::fie($name = '', $filter = false, $filter_flag = 0)

Reads and sanitises a value from $_ENV (INPUT_ENV).

Parameters

$name string

The $_ENV key.

Default: ''
$filter int

filter_var() constant. Defaults to FILTER_DEFAULT.

Default: false
$filter_flag int|array

Additional filter_var() flag(s).

Default: 0

Returns

mixed

fig() static

Form::fig($name = '', $filter_mode = false, $filter_flag = 0)

Reads and sanitises a value from $_GET (INPUT_GET).

Parameters

$name string

The $_GET key. Pass an empty string to receive the entire GET array.

Default: ''
$filter_mode mixed

Sanitisation mode — see sanitise(). false applies default sanitisation.

Default: false
$filter_flag int|array

Additional filter_var() flag(s).

Default: 0

Returns

mixed

files() static

Form::files($name = null)

Returns a $_FILES entry as an object, or all entries as an array. When the requested key is absent, returns an object with error set to UPLOAD_ERR_NO_FILE (4).

Parameters

$name string|null

The $_FILES key, or null to return the full $_FILES array.

Default: null

Returns

object|array

fip() static

Form::fip($name = '', $filter_mode = false, $filter_flag = 0)

Reads and sanitises a value from $_POST (INPUT_POST).

Parameters

$name string

The $_POST key. Pass an empty string to receive the entire POST array.

Default: ''
$filter_mode mixed

Sanitisation mode — see sanitise(). false applies default sanitisation.

Default: false
$filter_flag int|array

Additional filter_var() flag(s).

Default: 0

Returns

mixed

fis() static

Form::fis($name = '', $filter = false, $filter_flag = 0)

Reads and sanitises a value from $_SERVER (INPUT_SERVER).

Parameters

$name string

The $_SERVER key.

Default: ''
$filter int

filter_var() constant. Defaults to FILTER_DEFAULT.

Default: false
$filter_flag int|array

Additional filter_var() flag(s).

Default: 0

Returns

mixed

jsonEncode() static

Form::jsonEncode($array)

JSON-encodes a value and prepares it to be stored as a string column via the Model.

JSON objects (those whose encoded form starts with {) are wrapped in an extra {} layer before escapeModelEscape() runs. This is necessary because Model processes bound values through removeEscapes(escapeObject(...)) twice — once when building the INSERT/UPDATE clause and once inside execute(). Each pass strips one {} layer, so JSON objects need two layers to arrive at the database intact. JSON arrays and scalar values are not affected because they do not start with {.

Parameters

$array mixed

The value to encode.

Returns

string|mixed The prepared JSON string, or the original value when encoding fails.

pass() static deprecated

Form::pass($pass, $salt = '0')
Deprecated.

Use Security::pass() instead.

No description yet.

Parameters

$pass mixed
$salt mixed Default: '0'

pr() static

Form::pr($toBePrint)

Prints a string with HTML tags stripped and newlines converted to <br/> tags.

Parameters

$toBePrint mixed

The string to print.

sanitise() static

Form::sanitise($string, $option = false, $charset = 'utf-8')

Sanitises a value, protecting against XSS and injection.

$option controls the sanitisation mode:

  • false (default): strips HTML tags, normalises whitespace, and escapes common XSS vectors.
  • 'html': parses the value as an HTML fragment, removes <script> tags and on-* event attributes, then returns the sanitised inner HTML of the body.
  • 'json': decodes a JSON string and recursively sanitises its values, or passes through non-string values unchanged.
  • 'file': strips path-traversal sequences and characters that are illegal in filenames.
  • int / filter constant: delegates to filter_var() with the given filter and flag.

When $string is an array, each element is sanitised individually.

Parameters

$string mixed

The value to sanitise.

$option mixed

Sanitisation mode — see above.

Default: false
$charset string|int

Charset for 'html' mode (default 'utf-8'), or a filter flag for 'json' mode.

Default: 'utf-8'

Returns

mixed The sanitised value.

sanitiseObject() static

Form::sanitiseObject($value, $option = false, $charset = 'utf-8')

Sanitises a single value, handling objects by casting them to arrays first. Delegates to sanitise() for all actual sanitisation logic.

Parameters

$value mixed

The value to sanitise.

$option mixed

Sanitisation mode — see sanitise().

Default: false
$charset string|int

Charset or filter flag — see sanitise().

Default: 'utf-8'

Returns

mixed

start() static

Form::start($action = '', $method = 'post', $attr = '')

Renders an opening <form> tag with the given method, action, and optional extra attributes. When Security::$CSRFTokenConfig is enabled and the method is POST, hidden CSRF token fields are automatically injected.

Parameters

$action string

The form action URL.

Default: ''
$method string

The HTTP method: 'post' or 'get'.

Default: 'post'
$attr string|array

Extra HTML attributes as a raw string or an associative array.

Default: ''

val() static

Form::val($name, $filter_mode = false, $filter_flag = 0)

Reads from $_GET first; falls back to $_POST when the GET value is absent or null. Useful for endpoints that accept both forms of input.

Parameters

$name string

The key to look up in $_GET then $_POST.

$filter_mode mixed

Sanitisation mode — see sanitise().

Default: false
$filter_flag int|array

Additional filter_var() flag(s).

Default: 0

Returns

mixed

Generated from core/classes/Form.php (FrostMVC ).