[ic] Search parameters in tutorial

msquared msquared@digitalwizards.com.au
Thu, 1 Feb 2001 12:08:40 +0800

I've been playing with the tutorial (which is very informative, I might
add), and came across a problem.

I set up the search box on the tutorial site as per the instructions in
the tutorial:


However, it seems to search every field in the product table, not just the
ones that are listed.

It didn't seem to matter what I changed the sf (search field) to in the
[set testname][/set] tags.  I assume that sets a server-side session
variable, which is then referenced by the hidden form field mv_profile?

As a side issue, it seems that we can add interchange tags to user
comments on the tutorial.  You'll note that I made three tries at
indicating some interchange tags in the user comments before I finally got
it right.  :-)

Is that a potential security risk?

