473,395 Members | 2,713 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,395 software developers and data experts.

Export Excel

i have created a page that export in excel format some recordsets
extract from a database, i pass to that page the sql query string via
get

example:
href="export_excel.php?sql=<?=$sql?>"

it works fine but in the address bar and in the title bar (with
Explorer) it write the sql string that i pass to the page and i don't
like it

how can i solve that problem?

thanx (and sorry for my english)
Jul 17 '05 #1
2 3041
CogitoErgoDigito wrote:
i have created a page that export in excel format some recordsets
extract from a database, i pass to that page the sql query string via
get

example:
href="export_excel.php?sql=<?=$sql?>"

it works fine but in the address bar and in the title bar (with
Explorer) it write the sql string that i pass to the page and i don't
like it


When passing a variable via GET-parameters, You cannot avoid the
parameters appearing in the address bar, that's part of the concept.
MSIE is showing the string in the title because You aren't using a
<title>-tag, I suppose.
Use POST to submit Your string, and the address bar remains clear.

Do I have to tell You that submitting and executing full SQL statements
on a public page is _very_ dangerous?
Anyone can fumble with the statement (DELETE * FROM table, etc.), and
hiding the statement in a POST doesn't make it much safer, it's simply
not quite as obvious.
(If You're just using the script on Your private machine or in a
restricted area, it may be all right)

Rudi
Jul 17 '05 #2
Rudolf Horbas <rh*****@gmx.net> wrote in message news:<c2**********@svr7.m-online.net>...
When passing a variable via GET-parameters, You cannot avoid the
parameters appearing in the address bar, that's part of the concept.
MSIE is showing the string in the title because You aren't using a
<title>-tag, I suppose.
Use POST to submit Your string, and the address bar remains clear.

Do I have to tell You that submitting and executing full SQL statements
on a public page is _very_ dangerous?
Anyone can fumble with the statement (DELETE * FROM table, etc.), and
hiding the statement in a POST doesn't make it much safer, it's simply
not quite as obvious.
(If You're just using the script on Your private machine or in a
restricted area, it may be all right)

Rudi


Thank u much for your answer!
Now I pass values via post and in the address bar it show the page
name.
(I don't send the entire string but only the WHERE condition and it
comes from a page where it's only possible to choose some parameter)

tnx
Ciao
Jul 17 '05 #3

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

1
by: Matt | last post by:
I have an ASP page that calls ASP routines that I created that execute a database query and return the results to a recordset. I then iterate through the recordset and display the data in a table....
5
by: Maria L. | last post by:
Hi, I need to export the content of a DataGrid (in Windows application in C#), into an Excel spreadsheet. Anyone knows how to do this? Any code snippets would help! thanks a lot, Maria
2
by: Siu | last post by:
Hi, I use the following code to export and import a file Excel from resp. into a Web page with the following code: //EXPORT Response.Clear(); Response.Buffer = true; Response.ContentType =...
6
by: Elena | last post by:
I'm trying to export data to an Excel worksheet. I can export the data in the cell values perfectly. I need the code to change a header and footer for the worksheet, not for the columns. Is...
13
by: Hemant Sipahimalani | last post by:
The following piece of code is being used to export HTML to excel. HttpContext.Current.Response.ContentType = "application/vnd.ms-excel"...
5
by: Simon | last post by:
Dear reader, With the export command you can export a query to Excel. By activate this command a form pop's up with the following text:
1
by: smaczylo | last post by:
Hello, I've recently been asked to work with Microsoft Access, and while I feel quite comfortable with Excel, I'm at a complete loss with databases. If someone could help me with this issue I'm...
1
by: CoolFactor | last post by:
MY CODE IS NEAR THE BOTTOM I want to export this Access query into Excel using a command button on an Access form in the following way I describe below. Below you will find the simple query I am...
3
by: =?Utf-8?B?YzY3NjIyOA==?= | last post by:
Hi all, I have a question for you. I have a .csv file which has many lines of data. Each line has many data fields which are delimited by ",". Now I need to extract part of data from this...
2
hemantbasva
by: hemantbasva | last post by:
Note We need to have a template on server for generating report in multiple sheet as we do not had msoffice on server moreover this require a batch job to delete excel file created by the...
0
by: ryjfgjl | last post by:
In our work, we often receive Excel tables with data in the same format. If we want to analyze these data, it can be difficult to analyze them because the data is spread across multiple Excel files...
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
0
BarryA
by: BarryA | last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
1
by: nemocccc | last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...
0
by: Hystou | last post by:
There are some requirements for setting up RAID: 1. The motherboard and BIOS support RAID configuration. 2. The motherboard has 2 or more available SATA protocol SSD/HDD slots (including MSATA, M.2...
0
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers,...
0
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.