FrostMVC\Form
use FrostMVC\Form;
Input sanitisation, HTTP input helpers, and form rendering utilities.
All public methods are static. The primary entry points are:
| ::desanitise() | Reverses htmlspecialchars() encoding, restoring HTML entities to their original characters. |
| ::end() | Renders a closing </form> tag. |
| ::fic() | Reads and sanitises a value from $_COOKIE (INPUT_COOKIE). |
| ::fie() | Reads and sanitises a value from $_ENV (INPUT_ENV). |
| ::fig() | Reads and sanitises a value from $_GET (INPUT_GET). |
| ::files() | Returns a $_FILES entry as an object, or all entries as an array. When the requested key is absent, returns an object with error set to UPLOAD_ERR_NO_FILE (4). |
| ::fip() | Reads and sanitises a value from $_POST (INPUT_POST). |
| ::fis() | Reads and sanitises a value from $_SERVER (INPUT_SERVER). |
| ::jsonEncode() | JSON-encodes a value and prepares it to be stored as a string column via the Model. |
| ::pass() | — |
| ::pr() | Prints a string with HTML tags stripped and newlines converted to <br/> tags. |
| ::sanitise() | Sanitises a value, protecting against XSS and injection. |
| ::sanitiseObject() | Sanitises a single value, handling objects by casting them to arrays first. Delegates to sanitise() for all actual sanitisation logic. |
| ::start() | Renders an opening <form> tag with the given method, action, and optional extra attributes. When Security::$CSRFTokenConfig is enabled and the method is POST, hidden CSRF token fields are automatically injected. |
| ::val() | Reads from $_GET first; falls back to $_POST when the GET value is absent or null. Useful for endpoints that accept both forms of input. |
Form::desanitise($string)
Reverses htmlspecialchars() encoding, restoring HTML entities to their original characters.
| $string | string |
The encoded string. |
string
Form::end()
Renders a closing </form> tag.
Form::fic($name = '', $filter = false, $filter_flag = 0)
Reads and sanitises a value from $_COOKIE (INPUT_COOKIE).
| $name | string |
The $_COOKIE key. Default:'' |
| $filter | int |
filter_var() constant. Defaults to FILTER_DEFAULT. Default:false |
| $filter_flag | int|array |
Additional filter_var() flag(s). Default:0 |
mixed
Form::fie($name = '', $filter = false, $filter_flag = 0)
Reads and sanitises a value from $_ENV (INPUT_ENV).
| $name | string |
The $_ENV key. Default:'' |
| $filter | int |
filter_var() constant. Defaults to FILTER_DEFAULT. Default:false |
| $filter_flag | int|array |
Additional filter_var() flag(s). Default:0 |
mixed
Form::fig($name = '', $filter_mode = false, $filter_flag = 0)
Reads and sanitises a value from $_GET (INPUT_GET).
| $name | string |
The $_GET key. Pass an empty string to receive the entire GET array. Default:'' |
| $filter_mode | mixed |
Sanitisation mode — see sanitise(). false applies default sanitisation. Default:false |
| $filter_flag | int|array |
Additional filter_var() flag(s). Default:0 |
mixed
Form::files($name = null)
Returns a $_FILES entry as an object, or all entries as an array. When the requested key is absent, returns an object with error set to UPLOAD_ERR_NO_FILE (4).
| $name | string|null |
The $_FILES key, or null to return the full $_FILES array. Default:null |
object|array
Form::fip($name = '', $filter_mode = false, $filter_flag = 0)
Reads and sanitises a value from $_POST (INPUT_POST).
| $name | string |
The $_POST key. Pass an empty string to receive the entire POST array. Default:'' |
| $filter_mode | mixed |
Sanitisation mode — see sanitise(). false applies default sanitisation. Default:false |
| $filter_flag | int|array |
Additional filter_var() flag(s). Default:0 |
mixed
Form::fis($name = '', $filter = false, $filter_flag = 0)
Reads and sanitises a value from $_SERVER (INPUT_SERVER).
| $name | string |
The $_SERVER key. Default:'' |
| $filter | int |
filter_var() constant. Defaults to FILTER_DEFAULT. Default:false |
| $filter_flag | int|array |
Additional filter_var() flag(s). Default:0 |
mixed
Form::jsonEncode($array)
JSON-encodes a value and prepares it to be stored as a string column via the Model.
JSON objects (those whose encoded form starts with {) are wrapped in an extra {} layer before escapeModelEscape() runs. This is necessary because Model processes bound values through removeEscapes(escapeObject(...)) twice — once when building the INSERT/UPDATE clause and once inside execute(). Each pass strips one {} layer, so JSON objects need two layers to arrive at the database intact. JSON arrays and scalar values are not affected because they do not start with {.
| $array | mixed |
The value to encode. |
string|mixed The prepared JSON string, or the original value when encoding fails.
Form::pass($pass, $salt = '0')
Use Security::pass() instead.
No description yet.
| $pass | mixed |
|
| $salt | mixed |
Default: '0' |
Form::pr($toBePrint)
Prints a string with HTML tags stripped and newlines converted to <br/> tags.
| $toBePrint | mixed |
The string to print. |
Form::sanitise($string, $option = false, $charset = 'utf-8')
Sanitises a value, protecting against XSS and injection.
$option controls the sanitisation mode:
When $string is an array, each element is sanitised individually.
| $string | mixed |
The value to sanitise. |
| $option | mixed |
Sanitisation mode — see above. Default:false |
| $charset | string|int |
Charset for 'html' mode (default 'utf-8'), or a filter flag for 'json' mode. Default:'utf-8' |
mixed The sanitised value.
Form::sanitiseObject($value, $option = false, $charset = 'utf-8')
Sanitises a single value, handling objects by casting them to arrays first. Delegates to sanitise() for all actual sanitisation logic.
| $value | mixed |
The value to sanitise. |
| $option | mixed |
Sanitisation mode — see sanitise(). Default:false |
| $charset | string|int |
Charset or filter flag — see sanitise(). Default:'utf-8' |
mixed
Form::start($action = '', $method = 'post', $attr = '')
Renders an opening <form> tag with the given method, action, and optional extra attributes. When Security::$CSRFTokenConfig is enabled and the method is POST, hidden CSRF token fields are automatically injected.
| $action | string |
The form action URL. Default:'' |
| $method | string |
The HTTP method: 'post' or 'get'. Default:'post' |
| $attr | string|array |
Extra HTML attributes as a raw string or an associative array. Default:'' |
Form::val($name, $filter_mode = false, $filter_flag = 0)
Reads from $_GET first; falls back to $_POST when the GET value is absent or null. Useful for endpoints that accept both forms of input.
| $name | string |
The key to look up in $_GET then $_POST. |
| $filter_mode | mixed |
Sanitisation mode — see sanitise(). Default:false |
| $filter_flag | int|array |
Additional filter_var() flag(s). Default:0 |
mixed
Generated from core/classes/Form.php (FrostMVC ).