ID: 16155
Updated by: rlm@pricegrabber.com
Reported By: rlm@pricegrabber.com
Status: Open
Bug Type: Feature/Change Request
Operating System: RH 7.2
PHP Version: 4.1.2
New Comment:
No, it won't, because that will also add the variables to the global
namespace. This is not a feature request -- it's *making the system
work as advertised*. There already is -- or should be, if the writers
of the documentation were correct -- a way to disable global variable
imports, which ought to be the configuration lines
register_globals = Off
variables_order = ""
That is,
- register_globals should control the registration of globals, and
- variables_order should control the source(s) of and order of
global variable parsing.
Just like it says in the documentation:
"variables_order string
Set the order of the EGPCS (Environment, GET, POST, Cookie, Server)
variable parsing. The default setting of this directive is "EGPCS".
Setting this to "GP", for example, will cause PHP to completely ignore
environment variables, cookies and server variables, and to overwrite
any GET method variables with POST-method variables of the same name."
Notice how the above makes NO mention of whether track_vars is set --
but that doesn't matter, because track_vars IS ALWAYS SET ON! That
implies that variable tracking in HTTP_*_VARS should ALWAYS happen.
ALWAYS.
The tools to do this already exists. This is not a feature but a bug
-- the extant documentation describes a rationally behaving
environment, but PHP no longer conforms to it.
Previous Comments:
------------------------------------------------------------------------
[2002-07-10 18:21:53] philip@php.net
Just set the PHP predefined variables you want in the variables_order
directive. Like, GPCS or EGPCS. And turn register_globals off. This
will do what you want.
I'm turning this into a feature request and changing the summary. See
Rasmus' post/thread for details on this request.
Whoever decided that variables_order should be 'es' during your install
should be informed on the matter too.
------------------------------------------------------------------------
[2002-07-10 16:37:44] rlm@pricegrabber.com
See my earlier comments but the possibility of the combination of
track_vars=on and register_globals=off is entirely desirable. That is,
we want PHP to pick up variables from the URL, POST, cookies, etc. into
HTTP_GET_VARS etc. WITHOUT importing them into the namespace.
------------------------------------------------------------------------
[2002-07-10 14:09:36] philip@php.net
The various places are the: variables_order, register_globals, and
predefind variables manual entries.
track_vars documentation states it's always on as of 4.0.3, do you feel
this should be reworded? I'll add a reference to variables_order
there.
This bug remains open and I believe remains until a solution is found
that doesn't affect BC. Obviously some concern exists, see that
thread. There was a time when the register_globals directive didn't
even exist.
------------------------------------------------------------------------
[2002-07-10 13:46:01] rlm@pricegrabber.com
In WHICH "various places" is this misbehavior documented? And why is
it NOT documented in the one place it should be mandatory -- the
"track_vars" documentation?
http://www.php.net/manual/en/configuration.php#ini.track-vars
And finally -- since you brought it up -- why isn't track_vars
functional obsolescence documented along with that variable?
I've said it before, and in this same bug -- this behavior amounts to
poor design under the "least surprise" principle.
------------------------------------------------------------------------
[2002-07-10 13:13:10] philip@php.net
This behavior is documented in various places and is expected. When
the variables_order documentation says "PHP will completely ignore
them" it really means it. There was talk of adding additional
directives but nothing came of it (yet?). See:
http://marc.theaimsgroup.com/?l=php-dev&m=101194050211581
http://marc.theaimsgroup.com/?l=php-dev&m=101194642021528
On a related note, track_vars doesn't do anything as of PHP 4.0.3.
Also, even if variables_order lacks an E you can still use getenv() and
the E info is still shown in phpinfo(). So I guess PHP never
completely ignores E :)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/16155
--
Edit this bug report at http://bugs.php.net/?id=16155&edit=1