> That's where Javascript kicks in. You only need to use the javascript to
> modify your document (visual effect); you won't need it to submit to the
> server (the real action).

Oh yes, good point - even though (if he were still going to go the
JavaScript route) he'd modify the textarea using javascript, a regular
submit button could be used because it'll submit the current contents
of that textarea all the same.

>> also don't forget to sanitize the data you receive before committing
>> it to the database, or someone can hack the javascript and send an SQL
>> injection attack
> Or a XSS attack (Cross-site scripting). Basically, you want to check whether
> the string received by the server matches your own predefined list of colors
> before storing to the database.
