Slide 1

Slide 1 text

Forms make the web "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 2

Slide 2 text

Forms Best Practices Twitter @kevindees "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 3

Slide 3 text

Design Details "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 4

Slide 4 text

Forms must be fast. "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 5

Slide 5 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 6

Slide 6 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 7

Slide 7 text

Forms must be clear "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 8

Slide 8 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 9

Slide 9 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 10

Slide 10 text

☠ Placeholder Text "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 11

Slide 11 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 12

Slide 12 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 13

Slide 13 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 14

Slide 14 text

Forms must be mobile. "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 15

Slide 15 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 16

Slide 16 text

Think Differently ! "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 17

Slide 17 text

Code Considerations "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 18

Slide 18 text

1. Use UTF-8 2. CSRF 3. POST as array data 4. REST Hacking 5. Data Injection Order 6. Feedback "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 19

Slide 19 text

UTF-8? Really ! "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 20

Slide 20 text

Slide 21

Slide 21 text

CSRF "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 22

Slide 22 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 23

Slide 23 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 24

Slide 24 text

POST as array data "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 25

Slide 25 text

First Name Last Name Email

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 26

Slide 26 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 27

Slide 27 text

REST Hacking "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 28

Slide 28 text

.... "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 29

Slide 29 text

function rest_method($actual = false) { if($actual) { return $_SERVER['REQUEST_METHOD']; } return ! empty($_POST['_method']) ? strtoupper($_POST['_method']) : $_SERVER['REQUEST_METHOD']; } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 30

Slide 30 text

$user_controller = new \App\UserController; $rest_method = rest_method(); if( method_exists($user_controller, $rest_method) ) { $user_controller->{$rest_method}(); } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 31

Slide 31 text

Data Injection Order "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 32

Slide 32 text

1. Old Data If Errors 2. Model Data If Present "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 33

Slide 33 text

Email "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 34

Slide 34 text

function load_value( $name, $model = false ) { if( !empty($_SESSION['old'][$name]) ) { return $_SESSION['old'][$name]; } if( $model instanceof Model) { return $model->{$name}; } return ''; } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 35

Slide 35 text

if( $errors = has_form_errors() ) { $_SESSION['old'] = $_POST['user']; } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 36

Slide 36 text

Feedback "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 37

Slide 37 text

Words 1. Verbose 2. Vague "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 38

Slide 38 text

Your email address and password are wrong. or Your login is not working out. "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 39

Slide 39 text

Placement 1. Inline with field 2. Flash on top 3. Alert by overlay "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 40

Slide 40 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 41

Slide 41 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 42

Slide 42 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 43

Slide 43 text

Emotional 1. Life 2. Language "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 44

Slide 44 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 45

Slide 45 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 46

Slide 46 text

function has_form_errors() { $errors = []; if( is_not_email( $_POST['user']['email'] ) ) { $errors['user']['email'] = 'Opps! Check that email for us.' } if( empty($errors) ) { return false; } return $errors; } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 47

Slide 47 text

Email "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 48

Slide 48 text

Add emotion little effort "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 49

Slide 49 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 50

Slide 50 text

Email "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 51

Slide 51 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 52

Slide 52 text

"Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 53

Slide 53 text

Code for humans ! "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 54

Slide 54 text

... What about coders? ! "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 55

Slide 55 text

model = $model; $this->method = $method; $this->action = $action; $this->group = $group; $this->errors = $errors; } } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 56

Slide 56 text

class Form { .... function open() { $csrf = $_SESSION['_csrf']; $str = "action}\" method=\"POST\" accept-charset=\"utf-8\">"; $str .= ""; $str .= "method\">"; return $str; } function close() { return '

'; } function text($name) { return new \App\Field($name, $this); } } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 57

Slide 57 text

echo $form->text('email')->label('Email Address'); "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 58

Slide 58 text

name = $name; $this->form = $form; $this->value = load_value($name, $this->form->model); } } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 59

Slide 59 text

class Field { .... function label($label) { $this->label = $label; return $this; } function __toString() { $group = $this->form->group; $name = $this->name; $errors = $this->form->errors; ob_start(); // echo HTML return ob_get_clean(); } } "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 60

Slide 60 text

// echo HTML ?> label; ?> " value="value); ?>" />

Slide 61

Slide 61 text

$form = new \App\Form($model, 'POST', 'user.php', 'user', $errors); echo $form->open(); echo $form->text('email')->label('Email Address'); echo $form->close(); "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice

Slide 62

Slide 62 text

! Make YOUR forms amazing ! "Forms: Best Practices" by Kevin Dees // TypeRocket // Robojuice