Before a destructive action such as deleting a record, a confirmation dialog gives the user one more chance to continue or cancel. The original Plus2net example passes a record title and id into a JavaScript function and returns the result of confirm() to the link.
function confirmSubmit(title, id) {
const message = `Are you sure you want to delete the data? ${title} - ID=${id}`;
return window.confirm(message);
}
The deletion itself must still be enforced on the server. JavaScript confirmation is a user-interface safeguard, not authorization or security.
<?php
$title = 'Example title';
$id = 25;
$url = 'display_k.php?id=' . urlencode((string) $id) . '&todo=delete_k';
?>
<a href="<?= htmlspecialchars($url) ?>"
onclick="return confirmSubmit(<?= json_encode($title) ?>, <?= json_encode($id) ?>);">Delete</a>
The original page used an inline onclick handler because returning false cancels navigation. For a modern application, you can instead attach a listener and submit a form or request only after confirmation. Destructive operations should generally use POST/DELETE semantics with CSRF protection rather than a simple GET URL.
If JavaScript availability matters to a feature, see enable JavaScript and detect JavaScript support.
← Window Object Bookmark a page → Redirect Page →
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.
| deee | 28-03-2012 |
| Thanks, this works nicely and probably saved me a bunch of time. | |