469,898 Members | 1,591 Online
Bytes | Developer Community
New Post

Home Posts Topics Members FAQ

Post your question to a community of 469,898 developers. It's quick & easy.

replace query string with post method

I try to replace the following STATEMENT ONE with STATEMENT TWO. But it
doesn't work. How to make it work??? Thanks.

STATEMENT ONE:
<td colspan="10" align="center"><a
href="ExcelExport.asp?noIncludes=yes&sqlStr=<%=rep lace(Server.URLEncode(
strSQl),"'","`")%>"><img src='images/excel.gif' border='0' alt='Export
to Excel'></a></td>

STATEMENT TWO:
<FORM NAME='formname' METHOD=POST ACTION='ExcelExport.asp'
<INPUT TYPE='Hidden' NAME='strSQL' VALUE='" &
replace(Server.URLEncode(strSQl) & "'>
<tr><td BGCOLOR=E4E4E4 ID='bodytext' COLSPAN='8' align='center'><input
TYPE=SUBMIT value='export'></td></tr>
</form>
*** Sent via Developersdex http://www.developersdex.com ***
Don't just participate in USENET...get rewarded for it!
Jul 19 '05 #1
1 5002
What "doesn't work" about it? Do you get an error?
You have all kinds of syntax issues there. Is this in a response.write?
Where are the quotes? What's going on here?
Try:
%>

<FORM NAME="formname" METHOD="POST" ACTION="ExcelExport.asp">
<INPUT TYPE="Hidden" NAME="strSQL"
VALUE="<%=replace(Server.URLEncode(strSQl), "'", "''")%>">
BUT, what are you doing here? Why are you putting SQL in a form input? I
could go create a form like this and post it to your site:

<form action="http://yoursite.com/excelexport.asp" method="post">
<input name="strSQL" value="DROP TABLE
TheNameOfTheTableThatISawInAViewSSource">

Ray at work

"eddie wang" <ew***@kmg.com> wrote in message
news:Oq****************@TK2MSFTNGP09.phx.gbl...
I try to replace the following STATEMENT ONE with STATEMENT TWO. But it
doesn't work. How to make it work??? Thanks.

STATEMENT ONE:
<td colspan="10" align="center"><a
href="ExcelExport.asp?noIncludes=yes&sqlStr=<%=rep lace(Server.URLEncode(
strSQl),"'","`")%>"><img src='images/excel.gif' border='0' alt='Export
to Excel'></a></td>

STATEMENT TWO:
<FORM NAME='formname' METHOD=POST ACTION='ExcelExport.asp'
<INPUT TYPE='Hidden' NAME='strSQL' VALUE='" &
replace(Server.URLEncode(strSQl) & "'>
<tr><td BGCOLOR=E4E4E4 ID='bodytext' COLSPAN='8' align='center'><input
TYPE=SUBMIT value='export'></td></tr>
</form>
*** Sent via Developersdex http://www.developersdex.com ***
Don't just participate in USENET...get rewarded for it!

Jul 19 '05 #2

This discussion thread is closed

Replies have been disabled for this discussion.

Similar topics

3 posts views Thread by Harvey | last post: by
12 posts views Thread by Brian | last post: by
8 posts views Thread by skinnybloke | last post: by
3 posts views Thread by asd987 | last post: by
9 posts views Thread by Tony | last post: by
6 posts views Thread by JackpipE | last post: by
2 posts views Thread by =?Utf-8?B?TWFya19C?= | last post: by
1 post views Thread by Waqarahmed | last post: by
reply views Thread by Salome Sato | last post: by
By using this site, you agree to our Privacy Policy and Terms of Use.