C में Input Validation
In this page:
if (scanf("%specifier", &variable_name) == 1) {
// input was valid
} else {
// input failed
}
बिना Checked scanf क्यों Dangerous है
scanf उन items की संख्या return करता है जिन्हें उसने successfully पढ़ा, लेकिन उस return value को ignore करना आसान है -- अगर user letters type करे जहाँ एक number की उम्मीद थी, read fail हो जाता है, target variable पहले जो भी garbage था वह रखता है, और program bad data पर चलता रहता है।
उदाहरण: Why Unchecked scanf Is Dangerous
// Include standard input/output (printf, scanf)
#include <stdio.h>
// Program execution starts in main()
int main() {
int x;
// Declare result and set it to sscanf("abc", "%d", &x)
int result = sscanf("abc", "%d", &x);
// Print formatted text to the screen
printf("%d", result);
// Return 0 to signal that the program finished successfully
return 0;
}
Login to try C/C++/Java/PHP code in the editor
Return Value Check करना
scanf का return value आपने कितने conversions मांगे उससे compare करना -- if (scanf("%d", &x) == 1) -- defense की पहली line है, आपको एक uninitialized variable पर चुपचाप भरोसा करने की बजाय तुरंत एक failed read detect करने देते हुए।
उदाहरण: Checking the Return Value
// Include standard input/output (printf, scanf)
#include <stdio.h>
// Program execution starts in main()
int main() {
int x;
// Check whether sscanf("42", "%d", &x) == 1
if (sscanf("42", "%d", &x) == 1) {
// Print formatted text to the screen
printf("%d", x);
} else {
// Print formatted text to the screen
printf("Invalid input");
}
// Return 0 to signal that the program finished successfully
return 0;
}
Login to try C/C++/Java/PHP code in the editor
Input Buffer Clear करना
जब scanf एक number match करने में fail हो जाता है, invalid characters input buffer में बैठे रह जाते हैं और तुरंत अगली read को भी fail करा देंगे, इसलिए एक failed scan के बाद दोबारा try करने से पहले अगली newline तक characters discard करना चाहिए।
उदाहरण: Clearing the Input Buffer
// Include standard input/output (printf, scanf)
#include <stdio.h>
// Program execution starts in main()
int main() {
int x;
// Check whether sscanf("abc", "%d", &x) != 1
if (sscanf("abc", "%d", &x) != 1) {
// Print formatted text to the screen
printf("Discarded invalid input");
}
// Return 0 to signal that the program finished successfully
return 0;
}
Login to try C/C++/Java/PHP code in the editor
एक Successful Read के बाद Ranges Validate करना
एक successful scanf सिर्फ यह confirm करता है कि input का format सही था, यह नहीं कि value का कोई मतलब है -- एक option number पढ़ने वाले menu को अभी भी 5-item menu पर 99 जैसे out-of-bounds choice को reject करने के लिए एक अलग range check चाहिए।
उदाहरण: Validating Ranges After a Successful Read
// Include standard input/output (printf, scanf)
#include <stdio.h>
// Program execution starts in main()
int main() {
int choice;
sscanf("7", "%d", &choice);
// Check whether choice >= 1 && choice <= 5
if (choice >= 1 && choice <= 5) {
// Print formatted text to the screen
printf("Valid choice");
} else {
// Print formatted text to the screen
printf("Out of range");
}
// Return 0 to signal that the program finished successfully
return 0;
}
Login to try C/C++/Java/PHP code in the editor
Line-Based Input के लिए Safer Alternatives
fgets से एक पूरी line को एक buffer में पढ़ना और फिर इसे explicitly (sscanf या strtol से) parse करना अकेले scanf से ज़्यादा control देता है, क्योंकि आप decide करने से पहले raw input inspect कर सकते हैं कि इसे कैसे interpret करना है, और यह naturally scanf की dangling-buffer problem से बचता है।
उदाहरण: Safer Alternatives for Line-Based Input
// Include standard input/output (printf, scanf)
#include <stdio.h>
// Include general utilities (malloc, free, exit)
#include <stdlib.h>
// Program execution starts in main()
int main() {
char line[20] = "42\n";
// Declare value and set it to strtol(line, NULL, 10)
int value = strtol(line, NULL, 10);
// Print formatted text to the screen
printf("%d", value);
// Return 0 to signal that the program finished successfully
return 0;
}
Login to try C/C++/Java/PHP code in the editor
scanfका return value ignore करना, ताकि bad input को valid माना जाए।- एक failed read के बाद input buffer clear न करना, जो एक infinite loop cause करता है।
- सिर्फ यह check करना कि read succeed हुआ, और यह check करना भूल जाना कि value allowed range में है।
- C में output
printf(),puts(), newlines, और escape sequences से होता है जो control करते हैं कि text कैसे दिखता है। - Input
scanf()औरgets()से पढ़ा जाता है, और format specifiers C को बताते हैं कि हर value को कैसे interpret करना है। - Input validation आपके program के इस पर भरोसा करने से पहले user data check करता है।
Chapter Quiz — Complete all 7 topics to unlock
0/7 topics done
Complete these topics first: