Re: [Zend] Patch for unset()

From: Date: Thu, 15 Jun 2000 19:13:23 +0000
Subject: Re: [Zend] Patch for unset()
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-21462@lists.php.net to get a copy of this message
Right. That's what I was thinking. -adam On Thu, 15 Jun 2000, Zeev Suraski wrote: > > The Right Way to protect your variables is by using declare_globals = off, > and track_vars set to on (which is the default now). Nothing can get > outside the $HTTP_*_VARS[] that way. > > Zeev > > On Thu, 15 Jun 2000, Adam Trachtenberg wrote: > > > On Thu, 15 Jun 2000, Zeev Suraski wrote: > > > > > On Thu, 15 Jun 2000, Andrei Zmievski wrote: > > > > > > > On Thu, 15 Jun 2000, Faisal Nasim wrote: > > > > > | Why would you want that? > > > > > > > > > > Because I hate to put dozens of unset() > > > > > at the initialization for the global variables > > > > > I use, so no-one can preset the value (you > > > > > know how...) > > > > > > > > That would be a nice feature, actually. > > > > While I'm not explictly against letting unset() take multiple args, it > > seems like you're trying to modify a symptom to cure the disease. > > > > Wouldn't it be better to try to find a way to structure your code more > > securely? If people faking global vars is such a problem, surely there's > > more elegant ways of fixing it than embedding logic in every single page > > that iterates through a list of variables and unsets() them. > > > > Also, it's not like: > > > > $secrets = array('foo', 'bar', 'baz'); > > while (list($key, $val) = each($secrets)) { > > unset($$key); > > } > > > > is /that/ much worse than > > > > unset('foo', 'bar', 'baz'); > > > > -adam > > > > > > -- > Zeev Suraski <zeev@zend.com> > http://www.zend.com/ > -- / adam maccabee trachtenberg | it's what you think... \ \ adam@student.com | http://www.student.com /

« previous php.dev (#21462) next »