Re: [Zend] Patch for unset()
| From: | Zeev Suraski | Date: | Thu, 15 Jun 2000 19:11:29 +0000 |
| Subject: | Re: [Zend] Patch for unset() | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-21460@lists.php.net to get a copy of this message | ||
The Right Way to protect your variables is by using declare_globals = off,
and track_vars set to on (which is the default now). Nothing can get
outside the $HTTP_*_VARS[] that way.
Zeev
On Thu, 15 Jun 2000, Adam Trachtenberg wrote:
> On Thu, 15 Jun 2000, Zeev Suraski wrote:
>
> > On Thu, 15 Jun 2000, Andrei Zmievski wrote:
> >
> > > On Thu, 15 Jun 2000, Faisal Nasim wrote:
> > > > | Why would you want that?
> > > >
> > > > Because I hate to put dozens of unset()
> > > > at the initialization for the global variables
> > > > I use, so no-one can preset the value (you
> > > > know how...)
> > >
> > > That would be a nice feature, actually.
>
> While I'm not explictly against letting unset() take multiple args, it
> seems like you're trying to modify a symptom to cure the disease.
>
> Wouldn't it be better to try to find a way to structure your code more
> securely? If people faking global vars is such a problem, surely there's
> more elegant ways of fixing it than embedding logic in every single page
> that iterates through a list of variables and unsets() them.
>
> Also, it's not like:
>
> $secrets = array('foo', 'bar', 'baz');
> while (list($key, $val) = each($secrets)) {
> unset($$key);
> }
>
> is /that/ much worse than
>
> unset('foo', 'bar', 'baz');
>
> -adam
>
>
--
Zeev Suraski <zeev@zend.com>
http://www.zend.com/