(PHP 5 >= 5.2.0, PHP 7, PHP 8)
filter_input_array — Gets external variables and optionally filters them
$type, array|int $options = FILTER_DEFAULT, bool $add_empty = true): array|false|nullThis function is useful for retrieving many values without repetitively calling filter_input().
type
One of the INPUT_* constants.
The content of the superglobal that is being filtered is the original "raw" content provided by the SAPI, prior to any user modification to the superglobal. To filter a modified superglobal use filter_var_array() instead.
options
Either an associative array of options,
or the filter to apply to each entry,
which can either be a validation filter by using one of the
FILTER_VALIDATE_*
constants, or a sanitization filter by using one of the
FILTER_SANITIZE_*
constants.
The option array is an associative array where the key corresponds to a key in the input array and the associated value is either the filter to apply to this entry, or an associative array describing how and which filter should be applied to this entry.
The associative array describing how a filter should be applied
must contain the 'filter' key whose associated
value is the filter to apply, which can be one of the
FILTER_VALIDATE_*,
FILTER_SANITIZE_*,
FILTER_UNSAFE_RAW, or
FILTER_CALLBACK constants.
It can optionally contain the 'flags' key
which specifies any flags that apply to the filter,
and the 'options' key which specifies any options
that apply to the filter.
add_empty
Add missing keys as null to the return value.
On success, an array containing the values of the requested variables.
On failure, false is returned.
If the input array designated by type is not
populated, null is returned instead.
Missing entries from the input array are added to the returned array as
null if add_empty is true,
and are omitted entirely if it is false.
Unlike filter_input(),
the FILTER_NULL_ON_FAILURE flag does not change this:
a missing entry is always null.
An entry of the returned array will be false if the filter fails,
unless the FILTER_NULL_ON_FAILURE flag is used,
in which case it will be null.
With the FILTER_FORCE_ARRAY flag,
that failure value is wrapped in a one element array
like any other result.
Example #1 A filter_input_array() example
This example assumes a GET request to
?email=user@example.com&age=twenty&url=https://example.com.
The age entry fails because twenty is
not an integer; a value outside the
1 to 120 range would fail the same way.
<?php
$filters = [
'email' => FILTER_VALIDATE_EMAIL,
'age' => [
'filter' => FILTER_VALIDATE_INT,
'options' => ['min_range' => 1, 'max_range' => 120],
],
'url' => FILTER_VALIDATE_URL,
];
$result = filter_input_array(INPUT_GET, $filters);
var_dump($result);
?>The above example will output something similar to:
array(3) {
["email"]=>
string(16) "user@example.com"
["age"]=>
bool(false)
["url"]=>
string(19) "https://example.com"
}
Example #2 Filtering POST data with filter_input_array()
This example assumes a POST request with fields
username=<script>alert</script> and
comment=Hello World.
No missing field is submitted: because
add_empty defaults to true, it is still present in
the result, set to null.
<?php
$filters = [
'username' => FILTER_SANITIZE_SPECIAL_CHARS,
'comment' => FILTER_SANITIZE_SPECIAL_CHARS,
'missing' => FILTER_VALIDATE_INT,
];
$result = filter_input_array(INPUT_POST, $filters);
var_dump($result);
?>The above example will output something similar to:
array(3) {
["username"]=>
string(38) "<script>alert</script>"
["comment"]=>
string(11) "Hello World"
["missing"]=>
NULL
}
Example #3 Requesting an input type that is not populated
This example assumes a GET request.
Because the request carried no POST fields,
the input array designated by INPUT_POST is not
populated and null is returned instead of an array.
This applies to every input type:
a request with no query string yields null for
INPUT_GET as well.
<?php
var_dump(filter_input_array(INPUT_POST, ['a' => FILTER_VALIDATE_INT]));
?>The above example will output something similar to:
NULL
Note:
There is no
REQUEST_TIMEkey inINPUT_SERVERarray because it is inserted into the $_SERVER later.
FILTER_VALIDATE_*
FILTER_SANITIZE_*