Perl Tutorial on Perl CGI Programming

what is cgi ?

  • a common gateway interface, or cgi, is a set of standards that defines how information is exchanged between the web server and a custom script.

  • the cgi specs are currently maintained by the ncsa and ncsa defines cgi is as follows −

  • the common gateway interface, or cgi, is a standard for external gateway programs to interface with information servers such as http servers.

  • the current version is cgi/1.1 and cgi/1.2 is under progress.

web browsing

to understand the concept of cgi, lets see what happens when we click a hyper link available on a web page to browse a particular web page or url.

  • your browser contacts web server using http protocol and demands for the url, i.e., web page filename.

  • web server will check the url and will look for the filename requested. if web server finds that file then it sends the file back to the browser without any further execution otherwise sends an error message indicating that you have requested a wrong file.

  • web browser takes response from web server and displays either the received file content or an error message in case file is not found.

however, it is possible to set up http server in such a way so that whenever a file in a certain directory is requested that file is not sent back; instead it is executed as a program, and whatever that program outputs as a result, that is sent back for your browser to display. this can be done by using a special functionality available in the web server and it is called common gateway interface or cgi and such programs which are executed by the server to produce final result, are called cgi scripts. these cgi programs can be a perl script, shell script, c or c++ program, etc.

cgi architecture diagram

cgi architecture

web server support and configuration

before you proceed with cgi programming, make sure that your web server supports cgi functionality and it is configured to handle cgi programs. all the cgi programs to be executed by the web server are kept in a pre-configured directory. this directory is called cgi directory and by convention it is named as /cgi-bin. by convention perl cgi files will have extention as .cgi.

first cgi program

here is a simple link which is linked to a cgi script called hello.cgi. this file has been kept in /cgi-bin/ directory and it has the following content. before running your cgi program, make sure you have change mode of file using chmod 755 hello.cgi unix command.

#!/usr/bin/perl

print "content-type:text/html\r\n\r\n";
print '<html>';
print '<head>';
print '<title>hello word - first cgi program</title>';
print '</head>';
print '<body>';
print '<h2>hello word! this is my first cgi program</h2>';
print '</body>';
print '</html>';

1;

now if you click hello.cgi link then request goes to web server who search for hello.cgi in /cgi-bin directory, execute it and whatever result got generated, web server sends that result back to the web browser, which is as follows −

hello word! this is my first cgi program

this hello.cgi script is a simple perl script which is writing its output on stdout file, i.e., screen. there is one important and extra feature available which is first line to be printed content-type:text/html\r\n\r\n. this line is sent back to the browser and specifies the content type to be displayed on the browser screen. now you must have undertood basic concept of cgi and you can write many complicated cgi programs using perl. this script can interact with any other exertnal system also to exchange information such as a database, web services, or any other complex interfaces.

understanding http header

the very first line content-type:text/html\r\n\r\n is a part of http header, which is sent to the browser so that browser can understand the incoming content from server side. all the http header will be in the following form −

http field name: field content

for example −

content-type:text/html\r\n\r\n

there are few other important http headers, which you will use frequently in your cgi programming.

sr.no. header & description
1

content-type: string

a mime string defining the format of the content being returned. example is content-type:text/html

2

expires: date string

the date when the information becomes invalid. this should be used by the browser to decide when a page needs to be refreshed. a valid date string should be in the format 01 jan 1998 12:00:00 gmt.

3

location: url string

the url that should be returned instead of the url requested. you can use this filed to redirect a request to any other location.

4

last-modified: string

the date of last modification of the file.

5

content-length: string

the length, in bytes, of the data being returned. the browser uses this value to report the estimated download time for a file.

6

set-cookie: string

set the cookie passed through the string

cgi environment variables

all the cgi program will have access to the following environment variables. these variables play an important role while writing any cgi program.

sr.no. variables names & description
1

content_type

the data type of the content. used when the client is sending attached content to the server. for example file upload, etc.

2

content_length

the length of the query information. it's available only for post requests

3

http_cookie

returns the set cookies in the form of key & value pair.

4

http_user_agent

the user-agent request-header field contains information about the user agent originating the request. its name of the web browser.

5

path_info

the path for the cgi script.

6

query_string

the url-encoded information that is sent with get method request.

7

remote_addr

the ip address of the remote host making the request. this can be useful for logging or for authentication purpose.

8

remote_host

the fully qualified name of the host making the request. if this information is not available then remote_addr can be used to get ir address.

9

request_method

the method used to make the request. the most common methods are get and post.

10

script_filename

the full path to the cgi script.

11

script_name

the name of the cgi script.

12

server_name

the server's hostname or ip address.

13

server_software

the name and version of the software the server is running.

here is a small cgi program to list down all the cgi variables supported by your web server. click this link to see the result get environment

#!/usr/bin/perl

print "content-type: text/html\n\n";
print "<font size=+1>environment</font>\n";
foreach (sort keys %env) {
   print "<b>$_</b>: $env{$_}<br>\n";
}

1;

raise a "file download" dialog box?

sometime it is desired that you want to give option where a user will click a link and it will pop up a "file download" dialogue box to the user instead of displaying actual content. this is very easy and will be achived through http header.

this http header will be different from the header mentioned in previous section. for example, if you want to make a filename file downloadable from a given link then it's syntax will be as follows −

#!/usr/bin/perl

# http header
print "content-type:application/octet-stream; name = \"filename\"\r\n";
print "content-disposition: attachment; filename = \"filename\"\r\n\n";

# actual file content will go hear.
open( file, "<filename" );
while(read(file, $buffer, 100) ) {
   print("$buffer");
}

get and post methods

you must have come across many situations when you need to pass some information from your browser to the web server and ultimately to your cgi program handling your requests. most frequently browser uses two methods to pass this information to the web server. these methods are get method and post method. let's check them one by one.

passing information using get method

the get method sends the encoded user information appended to the page url itself. the page and the encoded information are separated by the ? character as follows −

http://www.test.com/cgi-bin/hello.cgi?key1=value1&key2=value2

the get method is the defualt method to pass information from a browser to the web server and it produces a long string that appears in your browser's location:box. you should never use get method if you have password or other sensitive information to pass to the server. the get method has size limitation: only 1024 characters can be passed in a request string.

this information is passed using query_string header and will be accessible in your cgi program through query_string environment variable which you can parse and use in your cgi program.

you can pass information by simply concatenating key and value pairs alongwith any url or you can use html <form> tags to pass information using get method.

simple url example: get method

here is a simple url which will pass two values to hello_get.cgi program using get method.

http://www.tutorialspoint.com/cgi-bin/hello_get.cgi?first_name=zara&last_name=ali

below is hello_get.cgi script to handle input given by web browser.

#!/usr/bin/perl

local ($buffer, @pairs, $pair, $name, $value, %form);
# read in text
$env{'request_method'} =~ tr/a-z/a-z/;
if ($env{'request_method'} eq "get") {
   $buffer = $env{'query_string'};
}
# split information into name/value pairs
@pairs = split(/&/, $buffer);
foreach $pair (@pairs) {
   ($name, $value) = split(/=/, $pair);
   $value =~ tr/+/ /;
   $value =~ s/%(..)/pack("c", hex($1))/eg;
   $form{$name} = $value;
}
$first_name = $form{first_name};
$last_name  = $form{last_name};

print "content-type:text/html\r\n\r\n";
print "<html>";
print "<head>";
print "<title>hello - second cgi program</title>";
print "</head>";
print "<body>";
print "<h2>hello $first_name $last_name - second cgi program</h2>";
print "</body>";
print "</html>";

1;

simple form example: get method

here is a simple example, which passes two values using html form and submit button. we are going to use the same cgi script hello_get.cgi to handle this input.

<form action = "/cgi-bin/hello_get.cgi" method = "get">
first name: <input type = "text" name = "first_name">  <br>

last name: <input type = "text" name = "last_name">
<input type = "submit" value = "submit">
</form>

here is the actual output of the above form coding. now you can enter first and last name and then click submit button to see the result.

first name:

last name:

passing information using post method

a more reliable method of passing information to a cgi program is the post method. this packages the information in exactly the same way as get methods, but instead of sending it as a text string after a ? in the url, it sends it as a separate message as a part of http header. web server provides this message to the cgi script in the form of the standard input.

below is the modified hello_post.cgi script to handle input given by the web browser. this script will handle get as well as post method.

#!/usr/bin/perl

local ($buffer, @pairs, $pair, $name, $value, %form);
# read in text
$env{'request_method'} =~ tr/a-z/a-z/;
if ($env{'request_method'} eq "post") {
   read(stdin, $buffer, $env{'content_length'});
} else {
   $buffer = $env{'query_string'};
}
# split information into name/value pairs
@pairs = split(/&/, $buffer);
foreach $pair (@pairs) {
   ($name, $value) = split(/=/, $pair);
   $value =~ tr/+/ /;
   $value =~ s/%(..)/pack("c", hex($1))/eg;
   $form{$name} = $value;
}
$first_name = $form{first_name};
$last_name  = $form{last_name};

print "content-type:text/html\r\n\r\n";
print "<html>";
print "<head>";
print "<title>hello - second cgi program</title>";
print "</head>";
print "<body>";
print "<h2>hello $first_name $last_name - second cgi program</h2>";
print "</body>";
print "</html>";

1;

let us take again same examle as above, which passes two values using html form and submit button. we are going to use cgi script hello_post.cgi to handle this input.

<form action = "/cgi-bin/hello_post.cgi" method = "post">
first name: <input type = "text" name = "first_name">  <br>

last name: <input type = "text" name = "last_name">

<input type = "submit" value = "submit">
</form>

here is the actual output of the above form coding, you enter first and last name and then click submit button to see the result.

first name:

last name:

passing checkbox data to cgi program

checkboxes are used when more than one option is required to be selected. here is an example html code for a form with two checkboxes.

<form action = "/cgi-bin/checkbox.cgi" method = "post" target = "_blank">
<input type = "checkbox" name = "maths" value = "on"> maths
<input type = "checkbox" name = "physics" value = "on"> physics
<input type = "submit" value = "select subject">
</form>

the result of this code is the following form −

maths physics

below is checkbox.cgi script to handle input given by web browser for radio button.

#!/usr/bin/perl

local ($buffer, @pairs, $pair, $name, $value, %form);
# read in text
$env{'request_method'} =~ tr/a-z/a-z/;
if ($env{'request_method'} eq "post") {
   read(stdin, $buffer, $env{'content_length'});
} else {
   $buffer = $env{'query_string'};
}
# split information into name/value pairs
@pairs = split(/&/, $buffer);
foreach $pair (@pairs) {
   ($name, $value) = split(/=/, $pair);
   $value =~ tr/+/ /;
   $value =~ s/%(..)/pack("c", hex($1))/eg;
   $form{$name} = $value;
}
if( $form{maths} ) {
   $maths_flag ="on";
} else {
   $maths_flag ="off";
}
if( $form{physics} ) {
   $physics_flag ="on";
} else {
   $physics_flag ="off";
}

print "content-type:text/html\r\n\r\n";
print "<html>";
print "<head>";
print "<title>checkbox - third cgi program</title>";
print "</head>";
print "<body>";
print "<h2> checkbox maths is : $maths_flag</h2>";
print "<h2> checkbox physics is : $physics_flag</h2>";
print "</body>";
print "</html>";

1;

passing radio button data to cgi program

radio buttons are used when only one option is required to be selected. here is an example html code for a form with two radio button −

<form action = "/cgi-bin/radiobutton.cgi" method = "post" target = "_blank">
<input type = "radio" name = "subject" value = "maths"> maths
<input type = "radio" name = "subject" value = "physics"> physics
<input type = "submit" value = "select subject">
</form>

the result of this code is the following form −

maths physics

below is radiobutton.cgi script to handle input given by the web browser for radio button.

#!/usr/bin/perl

local ($buffer, @pairs, $pair, $name, $value, %form);
# read in text
$env{'request_method'} =~ tr/a-z/a-z/;
if ($env{'request_method'} eq "post") {
   read(stdin, $buffer, $env{'content_length'});
} else {
   $buffer = $env{'query_string'};
}
# split information into name/value pairs
@pairs = split(/&/, $buffer);
foreach $pair (@pairs) {
   ($name, $value) = split(/=/, $pair);
   $value =~ tr/+/ /;
   $value =~ s/%(..)/pack("c", hex($1))/eg;
   $form{$name} = $value;
}
$subject = $form{subject};

print "content-type:text/html\r\n\r\n";
print "<html>";
print "<head>";
print "<title>radio - fourth cgi program</title>";
print "</head>";
print "<body>";
print "<h2> selected subject is $subject</h2>";
print "</body>";
print "</html>";

1;

passing text area data to cgi program

a textarea element is used when multiline text has to be passed to the cgi program. here is an example html code for a form with a textarea box −

<form action = "/cgi-bin/textarea.cgi" method = "post" target = "_blank">
<textarea name = "textcontent" cols = 40 rows = 4>
type your text here...
</textarea>
<input type = "submit" value = "submit">
</form>

the result of this code is the following form −

below is the textarea.cgi script to handle input given by the web browser.

#!/usr/bin/perl

local ($buffer, @pairs, $pair, $name, $value, %form);
# read in text
$env{'request_method'} =~ tr/a-z/a-z/;
if ($env{'request_method'} eq "post") {
   read(stdin, $buffer, $env{'content_length'});
} else {
   $buffer = $env{'query_string'};
}
# split information into name/value pairs
@pairs = split(/&/, $buffer);
foreach $pair (@pairs) {
   ($name, $value) = split(/=/, $pair);
   $value =~ tr/+/ /;
   $value =~ s/%(..)/pack("c", hex($1))/eg;
   $form{$name} = $value;
}
$text_content = $form{textcontent};

print "content-type:text/html\r\n\r\n";
print "<html>";
print "<head>";
print "<title>text area - fifth cgi program</title>";
print "</head>";
print "<body>";
print "<h2> entered text content is $text_content</h2>";
print "</body>";
print "</html>";

1;

passing drop down box data to cgi program

a drop down box is used when we have many options available but only one or two will be selected. here is example html code for a form with one drop down box

<form action = "/cgi-bin/dropdown.cgi" method = "post" target = "_blank">
<select name = "dropdown">
<option value = "maths" selected>maths</option>
<option value = "physics">physics</option>
</select>
<input type = "submit" value = "submit">
</form>

the result of this code is the following form −

below is the dropdown.cgi script to handle input given by web browser.

#!/usr/bin/perl

local ($buffer, @pairs, $pair, $name, $value, %form);
# read in text
$env{'request_method'} =~ tr/a-z/a-z/;
if ($env{'request_method'} eq "post") {
   read(stdin, $buffer, $env{'content_length'});
} else {
   $buffer = $env{'query_string'};
}
# split information into name/value pairs
@pairs = split(/&/, $buffer);
foreach $pair (@pairs) {
   ($name, $value) = split(/=/, $pair);
   $value =~ tr/+/ /;
   $value =~ s/%(..)/pack("c", hex($1))/eg;
   $form{$name} = $value;
}
$subject = $form{dropdown};

print "content-type:text/html\r\n\r\n";
print "<html>";
print "<head>";
print "<title>dropdown box - sixth cgi program</title>";
print "</head>";
print "<body>";
print "<h2> selected subject is $subject</h2>";
print "</body>";
print "</html>";

1;

using cookies in cgi

http protocol is a stateless protocol. but for a commercial website it is required to maintain session information among different pages. for example one user registration ends after transactions which spans through many pages. but how to maintain user's session information across all the web pages?

in many situations, using cookies is the most efficient method of remembering and tracking preferences, purchases, commissions, and other information required for better visitor experience or site statistics.

how it works

your server sends some data to the visitor's browser in the form of a cookie. the browser may accept the cookie. if it does, it is stored as a plain text record on the visitor's hard drive. now, when the visitor arrives at another page on your site, the cookie is available for retrieval. once retrieved, your server knows/remembers what was stored.

cookies are a plain text data record of 5 variable-length fields −

  • expires − the date the cookie will expire. if this is blank, the cookie will expire when the visitor quits the browser.

  • domain − the domain name of your site.

  • path − the path to the directory or web page that set the cookie. this may be blank if you want to retrieve the cookie from any directory or page.

  • secure − if this field contains the word "secure" then the cookie may only be retrieved with a secure server. if this field is blank, no such restriction exists.

  • name = value − cookies are set and retrviewed in the form of key and value pairs.

setting up cookies

it is very easy to send cookies to browser. these cookies will be sent along with the http header. assuming you want to set userid and password as cookies. so it will be done as follows −

#!/usr/bin/perl

print "set-cookie:userid = xyz;\n";
print "set-cookie:password = xyz123;\n";
print "set-cookie:expires = tuesday, 31-dec-2007 23:12:40 gmt";\n";
print "set-cookie:domain = www.tutorialspoint.com;\n";
print "set-cookie:path = /perl;\n";
print "content-type:text/html\r\n\r\n";
...........rest of the html content goes here....

here we used set-cookie http header to set cookies. it is optional to set cookies attributes like expires, domain, and path. it is important to note that cookies are set before sending magic line "content-type:text/html\r\n\r\n.

retrieving cookies

it is very easy to retrieve all the set cookies. cookies are stored in cgi environment variable http_cookie and they will have following form.

key1 = value1;key2 = value2;key3 = value3....

here is an example of how to retrieve cookies.

#!/usr/bin/perl
$rcvd_cookies = $env{'http_cookie'};
@cookies = split /;/, $rcvd_cookies;
foreach $cookie ( @cookies ) {
   ($key, $val) = split(/=/, $cookie); # splits on the first =.
   $key =~ s/^\s+//;
   $val =~ s/^\s+//;
   $key =~ s/\s+$//;
   $val =~ s/\s+$//;
   if( $key eq "userid" ) {
      $user_id = $val;
   } elsif($key eq "password") {
      $password = $val;
   }
}
print "user id  = $user_id\n";
print "password = $password\n";

this will produce the following result, provided above cookies have been set before calling retrieval cookies script.

user id = xyz
password = xyz123

cgi modules and libraries

you will find many built-in modules over the internet which provides you direct functions to use in your cgi program. following are the important once.