Bug #16308 Updated: unregister_globals() - a function that removes all vars by "register_globals"

From: Date: Wed, 27 Mar 2002 14:01:03 +0000
Subject: Bug #16308 Updated: unregister_globals() - a function that removes all vars by "register_globals"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-3481@lists.php.net to get a copy of this message
ID: 16308 Updated by: daniel@php.net Reported By: tapken@engter.de Status: Bogus Bug Type: Feature/Change Request Operating System: Linux 2.4 PHP Version: 4.1.2 New Comment: you can set register_globals = off on a vhost base with php_value in your httpd.conf and slowly migrate each user to the new config. Previous Comments: ------------------------------------------------------------------------ [2002-03-27 08:58:16] daniel@php.net and how do you think unregister_globals() should be able to distinguish between variables set by "register_globals" and those by the user? this will more like lead to a big mess. why not just switch it off? ------------------------------------------------------------------------ [2002-03-27 08:31:59] tapken@engter.de Hi all! The new globals vars ($_GET, $_POST, etc) are very nice but they do not bring more security if register_globals = on. Regrettably, many server admins are unable to set "register_globals = off" due to the fact that many scripts would broke. I would like to see a 'unregister_globals()'-Function (called at the beginning of a script) which parses the gpc-vars and unsets all normal vars with the same name (let's say it undoes register_globals' work). It would be nice if somebody would inform me if he has such a patch. bye, Roland ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=16308&edit=1

« previous php.bugs (#3481) next »