Re: [Zend] Patch for unset()
| From: | Adam Trachtenberg | Date: | Thu, 15 Jun 2000 19:13:23 +0000 |
| Subject: | Re: [Zend] Patch for unset() | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-21462@lists.php.net to get a copy of this message | ||
Right. That's what I was thinking.
-adam
On Thu, 15 Jun 2000, Zeev Suraski wrote:
>
> The Right Way to protect your variables is by using declare_globals = off,
> and track_vars set to on (which is the default now). Nothing can get
> outside the $HTTP_*_VARS[] that way.
>
> Zeev
>
> On Thu, 15 Jun 2000, Adam Trachtenberg wrote:
>
> > On Thu, 15 Jun 2000, Zeev Suraski wrote:
> >
> > > On Thu, 15 Jun 2000, Andrei Zmievski wrote:
> > >
> > > > On Thu, 15 Jun 2000, Faisal Nasim wrote:
> > > > > | Why would you want that?
> > > > >
> > > > > Because I hate to put dozens of unset()
> > > > > at the initialization for the global variables
> > > > > I use, so no-one can preset the value (you
> > > > > know how...)
> > > >
> > > > That would be a nice feature, actually.
> >
> > While I'm not explictly against letting unset() take multiple args, it
> > seems like you're trying to modify a symptom to cure the disease.
> >
> > Wouldn't it be better to try to find a way to structure your code more
> > securely? If people faking global vars is such a problem, surely there's
> > more elegant ways of fixing it than embedding logic in every single page
> > that iterates through a list of variables and unsets() them.
> >
> > Also, it's not like:
> >
> > $secrets = array('foo', 'bar', 'baz');
> > while (list($key, $val) = each($secrets)) {
> > unset($$key);
> > }
> >
> > is /that/ much worse than
> >
> > unset('foo', 'bar', 'baz');
> >
> > -adam
> >
> >
>
> --
> Zeev Suraski <zeev@zend.com>
> http://www.zend.com/
>
--
/ adam maccabee trachtenberg | it's what you think... \
\ adam@student.com | http://www.student.com /