Monday, January 4, 2010

Section 11.14. Test driving the new styles










11.14. Test driving the new styles



Now it's time to add those new properties to your "lounge.css" file and reload the page. Let's check out the changes: the headings, the images, and the text are all centered in the <div> and have a little more breathing room now that there's some padding in place. We've also got a little decoration at the top with the tiled cocktail image.


Wait just a sec... why does the text-align property affect the alignment of the images? Shouldn't it align only text? Seems like it should be called something else if it aligns images too.


The tiled image looks nice, and it only tiles horizontally.


We've got some padding here, and at the bottom and left...


... and everything's centered nicely.


Good point... it doesn't seem right, does it? But the truth is that text-align will align all inline content in a block element. So in this case, we're setting the property on the <div> block element and all its inline content is nicely centered as a result. Just remember that text-align, despite its name, works on any kind of inline element. One other thing to keep in mind: the text-align property should be set on block elements only. It has no effect if it's used directly on inline elements (like <img>).


That's interesting because I noticed the text inside the <div> is all inside other block elements, like <h2>, <h3>, and <p>. So, if textalign is aligning inline elements in the <div> block element, how is the text in these nested block elements getting aligned?


Good catch. All the text inside the <div> element is in nested block elements, but it is all aligned now. That's because these block elements inherit the text-align property from the <div>. So here's the difference: rather than the <div> itself aligning the text in the headings and the paragraphs (which it won't do because these are block elements), the headings and paragraphs are inheriting the text-align value of "center", and then aligning their own content to center.


So what? Well, if you think about it, this gives you a lot of leverage when you use a <div>, because you can wrap a section of content in a <div> and then apply styles to the <div> rather than each individual element. Of course, keep in mind that not all properties are inherited by default, so this won't work for all properties.



Sharpen your pencil



So now that you understand widths, what's the total width of the elixirs box? To start with, we know the content area is 200 pixels. We've also set some left and right padding that affects the width, as well as a border that's set to "thin". Just assume a thin border is 1 pixel thick, like it is on most browsers. And what about margins? We set a left margin value, but no right margin value, so the right margin is 0 pixels by default.


Here are all the properties that relate to width. Your job is to figure out the total width of the elixirs <div>.



border-width: thin;
width: 200px;
padding-right: 20px;
padding-bottom: 20px;
padding-left: 20px;
margin-left: 20px;








Lemon Breeze


The ultimate healthy drink, this elixir combines herbal botanicals, minerals, and vitamins with a twist of lemon into a smooth citrus wonder that will keep your immune system going all day and all night.



Chai Chiller


Not your traditional chai, this elixir mixes maté with chai spices and adds an extra chocolate kick for a caffeinated taste sensation on ice.



Black Brain Brew


Want to boost your memory? Try our Black Brain Brew elixir, made with black oolong tea and just a touch of espresso. Your brain will thank you for the boost.



Join us any evening for these and all our wonderful elixirs.














Anatomy of a CSS Rule








Anatomy of a CSS Rule


Let's start learning about how CSS is written by looking at a simple CSS rule. For example, here's a rule that makes all text in all paragraphs of your document red


While a p tag in the XHTML markup is enclosed in angle brackets, in the CSS style, you just write the tag name without the angle brackets.




p {color: red}


So if you have this XHTML markup



<p>This text is very important</p>


then it will be red.


A CSS rule is made up of two parts: the selector, which states which tag the rule selects, (or, as I like to say, which the rule the selector targets)in this case, a paragraphand the declaration, which states what happens when the rule is appliedin this case, the text displays in red. The declaration itself is made up of two elements: a property, which states what is to be affectedhere, the color of the textand a value, which states what the property is set tohere, red. It's worth taking a good look at this diagram (Figure 2.2) so that you are absolutely clear on these four terms; I'll be using them extensively as we move forward.


Figure 2.2. There are two main elements of a CSS rule and two sub-elements.









    Directing Implementation



    [ Team LiB ]









    Directing Implementation


    GP 2.6 Manage Configurations


    Place designated work products of the measurement and analysis process under appropriate levels of configuration management.


    Elaboration


    Examples of work products placed under configuration management include the following:



    • Specifications of base and derived measures


    • Data collection and storage procedures


    • Base and derived measurement data sets


    • Analysis results and draft reports


    • Data analysis tools






    GP 2.7 Identify and Involve Relevant Stakeholders


    Identify and involve the relevant stakeholders of the measurement and analysis process as planned.


    Elaboration


    Examples of activities for stakeholder involvement include the following:



    • Establishing measurement objectives and procedures


    • Assessing measurement data


    • Providing meaningful feedback to those responsible for providing the raw data on which the analysis and results depend






    GP 2.8 Monitor and Control the Process


    Monitor and control the measurement and analysis process against the plan for performing the process and take appropriate corrective action.


    Elaboration


    Examples of measures used in monitoring and controlling include the following:



    • Percentage of projects using progress and performance measures


    • Percentage of measurement objectives addressed











      [ Team LiB ]



      Loop-Based Sequencers





      Loop-Based
      Sequencers



      If trackers aren't your bag, then there is
      yet one more type of tool you can use that requires even less musical skill
      than sequencers or tracker: loop-based sequencers.



      Back in 1998 I happened upon Magix MusicMaker
      (
      style='color:#003399'>www.magix.com), a Windows
      application. At the time, I had both a Windows system and a Linux system. Since
      the program was only $20 I decided to check it out. To my surprise, it turned
      out to be a program that allowed me to create music, rich music, by dragging
      and dropping sound files (loops) onto a track
      in a sequencer. I could then stretch the loops to increase the length of time
      the loop was played. I was amazed at the simplicity of the entire process. In less
      than an hour, and without reading the manual, I was able to create a
      three-minute song I named "The Chase," which can be found at
      style='color:#003399'>www.mp3.com/digitalman. In
      less than six months I had created a total of 14 songs. My first CD, class=docemphasis1>It's Just the Galaxy,
      is now available at MP3.comlang=EN-GB>. My second CD, Majestic Relics, is
      on its way or might be there by the time you read this. Go to MP3.comlang=EN-GB> and listen to music that is possible with a loop-based sequencing
      program. You might be impressed.



      In addition to plugging my own music, I want
      to point out that loop-based sequencers, though easy to use, can be a little
      limiting on your creativity. It really depends, however, on your source of
      sounds. Similar to trackers, loop-based sequencers use sound files to produce
      the audio you hear. This means you will have to provide your own sound files
      for the sequencer.
      What sequencer, you ask? Well, since I had taught my
      wife how to log in and use a browser in Linux, I no longer had a need for a
      Windows system (you didn't think I actually used Windows for anything other
      than MusicMaker did you?). So my search for a loop-based sequencer for Linux
      began. I'm happy to report that I found one, MixMagic, at mixmagic.sourceforge.net.



      MixMagic is described not as a loop-based sequencer, but as
      "a hard drive sound-mixing program." It's just semantics. style='color:#003399'>Figure 20-6 shows the main composition window.
      You'll see that the loops (or samples) are layed out horizontally and that the
      tracks are layed out vertically. On the left is a directory list for your
      loops. You simply click-and-drag samples from the left over to the composition
      window on the right. Then you position the loop somewhere on the track and
      adjust its parameters to suit your needs. What could be easier? ("Turn on
      the radio" is not allowed as an answer.) All you really need to know about
      music is whether the samples you dragged to the right-side composition window
      sound good together. You see, each track plays left to right, as expected. All
      tracks are mixed together into a single stereo signal and played. This is
      similar to the final type of software technology I will be introducing, the
      digital multitrack recorder.



      style='font-size:10.5pt;font-family:Arial'>Figure 20-6. MixMagic tracks screen.




       





      Recipe 18.5. Eliminating SQL Injection










      Recipe 18.5. Eliminating SQL Injection



      18.5.1. Problem


      You need to eliminate

      SQL injection vulnerabilities in your PHP applications.




      18.5.2. Solution


      Use a database library such as PDO that performs the proper escaping for your database:


      <?php

      $db = new PDO('mysql:host=localhost;dbname=users',
      $_SERVER['DB_USER'],
      $_SERVER['DB_PASSWORD']);

      $statement = $db->prepare("INSERT
      INTO users (username, password)
      VALUES (:username, :password)");

      $statement->bindParam(':username', $clean['username']);
      $statement->bindParam(':password', $clean['password']);

      $statement->execute();

      $db = NULL;

      ?>





      18.5.3. Discussion


      Using bound parameters ensures your data never enters a context where it is considered to be anything except raw data, so no value can possibly modify the format of the SQL query.


      If you do not have access to PDO, you can use a database library written in PHP, such as

      PEAR::DB, that offers a similar feature:


      <?php

      $st = $db->query('INSERT
      INTO users (username, password)
      VALUES (?, ?)',
      array($clean['username'], $clean['password']));

      ?>



      Although this method still intermingles your data with the SQL query, PEAR::DB ensures that the data is quoted and escaped properly, so there is no practical risk of SQL injection.




      18.5.4. See Also


      Chapter 10 for more information about PDO, particularly Recipes Recipe 10.6 and Recipe 10.7; documentation on PDO at http://www.php.net/pdo; on PEAR::DB at http://pear.php.net/manual/en/package.database.db.php.













      Directing Implementation



      [ Team LiB ]









      Directing Implementation


      GP 3.2 Collect Improvement Information


      Collect work products, measures, measurement results, and improvement information derived from planning and performing the project monitoring and control process to support the future use and improvement of the organization's processes and process assets.



      GG 4 Institutionalize a Quantitatively Managed Process


      The process is institutionalized as a quantitatively managed process.


      GP 4.1 Establish Quantitative Objectives for the Process

      Establish and maintain quantitative objectives for the project monitoring and control process that address quality and process performance based on customer needs and business objectives.



      GP 4.2 Stabilize Subprocess Performance

      Stabilize the performance of one or more subprocesses to determine the ability of the project monitoring and control process to achieve the established quantitative quality and process-performance objectives.




      GG 5 Institutionalize an Optimizing Process


      The process is institutionalized as an optimizing process.


      GP 5.1 Ensure Continuous Process Improvement

      Ensure continuous improvement of the project monitoring and control process in fulfilling the relevant business objectives of the organization.



      GP 5.2 Correct Root Causes of Problems

      Identify and correct the root causes of defects and other problems in the project monitoring and control process.









        [ Team LiB ]



        Section 5.11.&nbsp; Frequently Asked Questions










        5.11. Frequently Asked Questions


        The following Frequently Asked Questions, answered by the authors of this book, are designed to both measure your understanding of the concepts presented in this chapter and to assist you with real-life implementation of these concepts. To have your questions about this chapter answered by the author, browse to www.syngress.com/solutions and click on the "Ask the Author" form. You will also gain access to thousands of other FAQs at ITFAQnet.com.


        Q: Can I really customize COBIT?


        A: Yes. However, prior to formalizing any processes or documentation based on your customizations, you will want to run it by your auditor.


        Q: Can the customization really be that simple?


        A: Yes, as long as you allow your environment to drive the process. However, keep in mind that you will need to justify your decisions.


        Q: Can I use the example forms?


        A: Yes, you can use any example forms, but you should format them to work best in your environment. These examples were developed to cover many of the items in the Planning and Organization domain.


        Q: Is there a particular type of environment in which COBIT works better?


        A: No. The COBIT guidelines are platform and environment agnostic.


        Q: If COBIT is so cumbersome, why should I use it?


        A: Because the guidelines are sound. However, we should apply another quality principle when looking at COBIT guidelines: the 80/20 rule.


        Q: Can I use my exiting policies?


        A: Yes, but you may have to make some slight modifications. The main thing to remember is that they need to be documented and support a control. By using a tool such as Wiki, the collaborative effort between you and your auditors becomes much easier to manage and track.


        Q: I am interested in learning more about Wiki collaboration in general; where can I get more information?


        A: Wiki is fast becoming an important collaboration tool, and we have applied it to some very specific functions. There are many Wikis in the open source world (in fact, a freshmeat.net search yielded 118 projects!). Here are a few of the most popular:


        • WikkiTikkiTavi, what eGroupware is based onhttp://tavi.sourceforge.net/.

        • Twiki, a full-blown collaboration serverhttp://twiki.org/.

        • Tiki CMS/Groupware, an interesting content management system Wikihttp://tikiwiki.org/.

        • PhpWiki, WikiWikiWeb clone written in PHPhttp://phpwiki.sourceforge.net/.