Forums / General Questions / PHP inside ezpages

PHP inside ezpages

Views: 54,189

Results 61 to 80 of 114
26 Sep 2009, 5:39 PM
#61
lndlyb4 avatar

lndlyb4

New Zenner

Join Date:
Mar 2009
Posts:
78
Plugin Contributions:
0

PHP inside ezpages

I think this piece of code in the header of the ez pages (includes/modules/pages/page/) is what is sending the form back to the index page of my gallery.

$ezpage_id = (int)$_GET['id'];
if ($ezpage_id == 0) zen_redirect(zen_href_link(FILENAME_DEFAULT));

It seems that, since the ez page id is not being passed from the form, it is being set to 0, and therefore re-directing to the default page. (a whole lot of guessing from a fledgling phper) If I can just figure out how to pass the ez page id, I might have this solved.

Otherwise, I will have to resort to setting this up outside the ezpage, as Dr. Byte has suggested (I'm reluctant to give up because I've spent days on this. Insert smiley here.)

All input is much appreciated.

Bill

26 Sep 2009, 6:03 PM
#62
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PHP inside ezpages

:eek:> lndlyb4:

<?php include ("http://www.blackoliveeastnursery.net/zenCart_boe/priceManager/priceList_ezInclude.php");?>

I'm surprised that works, since most servers who pay any attention to security at all will strictly prohibit using a URL in an include() or require() statement.
A MUCH safer approach would be to specify the physical path to the .php file, not a URL to it.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

26 Sep 2009, 6:10 PM
#63
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PHP inside ezpages

lndlyb4:

As I mentioned in my post, if I can just get the Action part of the form to send the page and id, I bet it would work.

<form id="searchForm"action="http://www.blackoliveeastnursery.net/zenCart_boe/index.php?main_page=page&id=7" method="GET">

...

It seems that, since the ez page id is not being passed from the form, it is being set to 0, and therefore re-directing to the default page.

You could try forcing some additional form parameters by adding the main_page and id fields to your HTML inside your form, on the next line after your <form> tag:```
<input type="hidden" name="main_page" value="page" />
<input type="hidden" name="id" value="7" />


(You'll be relieved to know that that's not PHP at all ... it's HTML :) )

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

26 Sep 2009, 6:20 PM
#64
lndlyb4 avatar

lndlyb4

New Zenner

Join Date:
Mar 2009
Posts:
78
Plugin Contributions:
0

Re: PHP inside ezpages

I'm surprised that works, since most servers who pay any attention to security at all will strictly prohibit using a URL in an include() or require() statement.
A MUCH safer approach would be to specify the physical path to the .php file, not a URL to it.

Yes, I think at the time I was too lazy to figure out the physical path, so I just put in the url to get to the include file.

You could try forcing some additional form parameters by adding the main_page and id fields to your HTML inside your form, on the next line after your <form> tag:
Code:

<input type="hidden" name="main_page" value="page" /> <input type="hidden" name="id" value="7" />

Thank you. I will give this a try.

I appreciate your patience with me. Right now I am re-arranging furniture in the dark. :smile:

26 Sep 2009, 6:51 PM
#65
lndlyb4 avatar

lndlyb4

New Zenner

Join Date:
Mar 2009
Posts:
78
Plugin Contributions:
0

Re: PHP inside ezpages

Dr Byte,

I think you're on to something here.

I added the hidden inputs you suggested and I am now no longer being re-directed to the index page. In fact I remain on the price list (ez page #7) AND the correct category id is being passed based on the selection I make from the drop down box.

The url for the page is as follows:

http://blackoliveeastnursery.net/zenCart_boe/index.php?main_page=page&id=7&categoryChoice=13

However, the list is not filtering from the category id in the url. The entire list continues to display.

The query in the include file is appended as such:

if (isset($_GET['categoryChoice']) && $_GET['categoryChoice'] != "All")
$query .= " AND p.master_categories_id = '".mysql_real_escape_string($_GET['categoryChoice'])."'";

Outside of the ez page, this works correctly and filters the list by category.

If I can get the query to read the category id in the url, I may be home free. (I wish I had a nickle for every time I thought that!)

Bill

26 Sep 2009, 8:12 PM
#66
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PHP inside ezpages

Well ... putting this in an ezPage, after making the edit to tpl_page_default.php as you said you did, produces the desired results for me:```

<form id="searchForm" action="/zc138/index.php" method="GET"> <input type="hidden" name="main_page" value="page" /> <input type="hidden" name="id" value="7" /> <select id="categoryName" name="categoryChoice" style="text-align:center;"> <option value="All">All</option> <option value="25">Begonias</option> <option value="31">Butterfly Plants</option> <option value="7">Cactus/Succulents</option> <option value="29">Ferns</option> <option value="27">Florida Natives</option> <option value="3">Flowering Shrubs</option> <option value="17">Flowering Trees</option> <option value="28">Foliage Shrubs</option> <option value="11">Fragrant Plants</option> <option value="16">Fruit Trees</option> <option value="10">Fruiting Plants</option> <option value="5">Ground Cover</option> <option value="13">Hanging Baskets</option> <option value="2">Hedges</option> <option value="30">Interior Plants</option> <option value="13">New Releases</option> <option value="9">Orn. Grasses</option> <option value="22">Orn. Trees</option> <option value="23">Palms</option> <option value="19">Patio Trees</option> <option value="6">Perennials</option> <option value="32">Roses</option> <option value="26">Seasonal</option> <option value="8">Shade Plants</option> <option value="21">Shade Trees</option> <option value="20">Street Trees</option> <option value="12">Tropicals/Exotics</option> <option value="4">Vines</option> </select>
<input type ="submit" value ="Show Plants">
</form> <p>GET params=<br /><pre> <?php echo print_r($_GET, TRUE); ?></pre> </p> <p> <?php $query = 'BASE'; if (isset($_GET['categoryChoice']) && $_GET['categoryChoice'] != "All") $query .= " AND p.master_categories_id = '".mysql_real_escape_string($_GET['categoryChoice'])."'"; echo $query; ?> </p> ```ie: if I choose "Butterfly Plants", I get the following output, exactly as expected:``` GET params=

Array
(
[main_page] => page
[id] => 7
[categoryChoice] => 31
)
BASE AND p.master_categories_id = '31'

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

27 Sep 2009, 2:57 PM
#67
lndlyb4 avatar

lndlyb4

New Zenner

Join Date:
Mar 2009
Posts:
78
Plugin Contributions:
0

Re: PHP inside ezpages

hhhmmmm...

This is very strange. I inserted the test code into my include page and I get the following results:

Array
(
)

SELECT * FROM

zen_products p,
zen_products_description pd,
zen_products_price pr,
zen_categories_description cd

WHERE p.products_id = pd.products_id AND
p.master_categories_id = cd.categories_id AND
p.products_id = pr.products_id order by products_name

The " AND p.master_categories_id = '".mysql_real_escape_string($_GET['categoryChoice'])" is not being echoed.

Yet, in the url in the address bar, I have this

http://blackoliveeastnursery.net/zenCart_boe/index.php?main_page=page&id=7&categoryChoice=25

Which seems correct.

Also, I would like to implement your suggestion below to make sure that is not what is hanging this up. I am confused about the physical path because I'm not sure which file I am pulling the include into.

I'm surprised that works, since most servers who pay any attention to security at all will strictly prohibit using a URL in an include() or require() statement.
A MUCH safer approach would be to specify the physical path to the .php file, not a URL to it.

thanks

27 Sep 2009, 4:30 PM
#68
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PHP inside ezpages

lndlyb4:

Array
(
)That tells you that the entire $_GET is no longer populated at that point. You must have something extra in your system to strip out all $_GET variable data by the time your page is called.
lndlyb4:

The " AND p.master_categories_id = '".mysql_real_escape_string($_GET['categoryChoice'])" is not being echoed.Same reason.

lndlyb4:

Also, I would like to implement your suggestion below to make sure that is not what is hanging this up. I am confused about the physical path because I'm not sure which file I am pulling the include into.
Well, since the file exists inside your Zen Cart site, you can probably just use something relative to that location, ie: perhaps:
include('priceManager/priceList_ezInclude.php');

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

27 Sep 2009, 6:07 PM
#69
lndlyb4 avatar

lndlyb4

New Zenner

Join Date:
Mar 2009
Posts:
78
Plugin Contributions:
0

Re: PHP inside ezpages

Dr Byte,

Thank you for confirming my suspicion about that.

When I get a chance I will rummage around in some of the files listed below that affect the ez pages to see if I can tell what's interfering with the GET. (Although, I think its a bit over my head.)

tpl_page_default.php
header_php.php
ezpages.php
others??

I think I am at the point where I need to take a different tack and create the page outside of Zen Cart and just add my own login page to it. This may be the best way anyway, because I was planning to add more filtering capabilities to the page and would have likely run into more coding mysteries.

You have been very gracious to spend so much time on this issue, although I did not solve it, I learned a lot from you along the way.

p.s.

Also thank you for the form you posted. This is probably something I can use in the future.

thank you

Bill

27 Sep 2009, 6:44 PM
#70
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: PHP inside ezpages

Sometimes it's good to do a quick review of everything that's been changed on your site ... often that'll reveal clues: http://www.zen-cart.com/wiki/index.php/Troubleshoot_-_Diagnosing_Obscure_Issues

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

13 Nov 2009, 7:20 PM
#71
tecbrat avatar

tecbrat

Zen Follower

Join Date:
Feb 2005
Posts:
239
Plugin Contributions:
0

Re: PHP inside ezpages

<form id="searchForm"action="http://www.blackoliveeastnursery.net/zenCart_boe/index.php?main_page=page&id=7" method="GET">

I wish I had seen this earlier so I could have helped you. I ran in to this problem and found the reason and the fix. Using the "GET" method nullifies the query string (the part after the ?) of your action. I usually switch to POST instead, but adding the hidden fields should work too.

16 Dec 2009, 5:12 AM
#72
froasis avatar

froasis

New Zenner

Join Date:
Dec 2009
Posts:
5
Plugin Contributions:
0

Re: PHP inside ezpages

This worked like a charm. (Tim's method). My next concern is the mention of security. Does the security issue come into play if I am the only one accessing the admin site? If so is there a way to only allow includes in php and only from a certain directory with limited access. Could maybe be incorporated into a plugin with drop downs for reference for the optional includes on the editor page.

4 Oct 2010, 11:26 PM
#73
makenoiz avatar

makenoiz

Zen Follower

Join Date:
Mar 2006
Posts:
284
Plugin Contributions:
0

Re: PHP inside ezpages

Is this still the preferred method for including PHP in EZ Pages (EZ-Pages) .?

http://www.zen-cart.com/forum/showthread.php?t=37252&page=6

I was hoping there was something easier more "out of the box" per se, as I cant get FCKeditor installed.

Thanks

1.3.8a Modded

22 stores and counting! Ive been zenned.

5 Oct 2010, 5:42 AM
#74
makenoiz avatar

makenoiz

Zen Follower

Join Date:
Mar 2006
Posts:
284
Plugin Contributions:
0

Re: PHP inside ezpages

Got fckeditor installed just fine and the above method works just fine. Less and Less folks are sticking to straight html any more.... so Im really surprised that PHP inclusion in ez pages this is not just a default feature of ZC in the most recent versions. Maybe for security issues. Anyway, the above link will tell you how to do it if you need it, and it DOES work.

22 stores and counting! Ive been zenned.

11 Oct 2010, 5:30 PM
#75
tecbrat avatar

tecbrat

Zen Follower

Join Date:
Feb 2005
Posts:
239
Plugin Contributions:
0

Re: PHP inside ezpages

makenoiz:

... Im really surprised that PHP inclusion in ez pages this is not just a default feature of ZC in the most recent versions...

I submitted this thread to the code suggestion forum.

1 Jan 2011, 2:07 AM
#76
finlander avatar

finlander

Zen Follower

Join Date:
Oct 2010
Location:
Idaho
Posts:
293
Plugin Contributions:
0

Re: PHP inside ezpages

I want to show the grid of top-level categories on the main page. I do not want to do this the simple way (flipping that switch in Admin), because then the home page is viewed as a top-level cat page. The reason I don't want that, is because then flipping the switch for New Prods box, Featured Prods box, etc, to show or not to show on ACTUAL top-level cat pages will result in New Prods, etc., also showing on the home page, since the home page has essentially become a top-level cat. In other words, I want to maintain separate control for New Prods box showing on home page vs. showing on true top-level cat pages.

So, the goal is to have home page w/ grid of top-level cats, but also have separate control of New Prods box, etc., for ACTUAL top-level cat pages.

To accomplish this, I thought I could simply put the php code (for calling the grid) into the define_main_page file. That way, home page is not viewed as a top-level cat, and so New Prods box, etc., can be turned on and off on ACTUAL top-level cat pages, while leaving New Prods box OFF on true home page.

Sadly, it is not working. The php won't pull through. All I need to do is make the following code work on define_main_page.php. Anyone know how?

<?php require($template->get_template_dir('tpl_modules_category_row.php',DIR_WS_TEMPLATE, $current_page_base,'templates'). '/tpl_modules_category_row.php'); ?>

thanks ..

1 Jan 2011, 2:41 AM
#77
gjh42 avatar

gjh42

Black Belt

Join Date:
Jul 2005
Location:
Upstate NY
Posts:
21,876
Plugin Contributions:
8

Re: PHP inside ezpages

A better (easier) method may be to add a test to the output code that produces the centerboxes to only execute if $this_is_home_page is false.

if (!$this_is_home_page) {
//run centerbox code
}

1 Jan 2011, 3:16 AM
#78
finlander avatar

finlander

Zen Follower

Join Date:
Oct 2010
Location:
Idaho
Posts:
293
Plugin Contributions:
0

Re: PHP inside ezpages

thanks Glenn, good thinking, better to supress in this case than to try to create. Thank you..

1 Jan 2011, 3:58 AM
#79
finlander avatar

finlander

Zen Follower

Join Date:
Oct 2010
Location:
Idaho
Posts:
293
Plugin Contributions:
0

Re: PHP inside ezpages

Glenn, it seems to work fine, but could you take a glance at how I added the code to the tpl_modules_whats_new.php file? I'm not too good with php and don't want to foul up validation or break some other thing inadvertently ..
(of course, I did do this in an override directory/file)

The code in red is what I added to the existing code of this file.

<?php /** * Module Template * * @package templateSystem * @copyright Copyright 2003-2005 Zen Cart Development Team * @copyright Portions Copyright 2003 osCommerce * @license <http://www.zen-cart.com/license/2_0.txt> GNU Public License V2.0 * @version $Id: tpl_modules_whats_new.php 2935 2006-02-01 11:12:40Z birdbrain $ */ $zc_show_new_products = false; include(DIR_WS_MODULES . zen_get_module_directory(FILENAME_NEW_PRODUCTS)); ?>

<?php if (!$this_is_home_page) { ?>

<!-- bof: whats_new --> <?php if ($zc_show_new_products == true) { ?> <div class="centerBoxWrapper" id="whatsNew"> <?php require($template->get_template_dir('tpl_columnar_display.php',DIR_WS_TEMPLATE, $current_page_base,'common'). '/tpl_columnar_display.php'); ?> </div> <?php } ?> <!-- eof: whats_new -->

<?php } ?>

5 Jan 2011, 3:24 PM
#80
gjh42 avatar

gjh42

Black Belt

Join Date:
Jul 2005
Location:
Upstate NY
Posts:
21,876
Plugin Contributions:
8

Re: PHP inside ezpages

That added code should work fine; however, there is an existing line that would nullify it:

$zc_show_new_products = false;

There is nothing to change that initial setting, so the sidebox will never display. You could relocate your test to set
$zc_show_new_products = true;
in the correct circumstances, or you could just change false to true in that line and leave the file as is. Either method would work fine.

Actually, I notice that the module file is called after the show variable is set, and there could be a resetting test in there that would product correct operation. Don't change this file unless experience shows you need to.