Re: PHP File Upload Security Hole - Still No Fix?
| From: | Chuck Hagenbuch | Date: | Tue, 05 Sep 2000 15:23:29 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32195@lists.php.net to get a copy of this message | ||
Quoting Jon Ribbens <jon+php-dev@unequivocal.co.uk>:
> There are reasons for all of them. Feel free to ask and I will explain.
Maybe if you included your reasons along with your suggestions, you might
not come across as quite so high-and-holy, and you might not alienate so
many people right off.
> I agree that not adding the slashes is more flexible, but this is only
> an advantage if 'add slashes but not quotes' is actually an operation
> you would ever want to do. I have never, so far as I can recall, needed
> to do this. Have you? What sort of situation are you envisaging where it
> would be useful?
I can see your point. I can think of lots of reasons, but they're mainly
differences in coding style - if you're building up a query string
dynamically, not having the quotes be part of addslashes gives you more
flexibility in how you do it.
Backwards compatibility is a consideration, though. It's not really feasible
to consider changing the behavior of a function that's been around that long
and is as widely used. Of course, adding a _new_ one is entirely possible...
-chuck
--
Charles Hagenbuch, <chuck@horde.org>
--
"It's not the size of the boat that makes the wave,
it's the motion of the ocean." - Junebug Jabbo Jones