RE: [PHP-DEV] Security?

From: Date: Wed, 04 Jul 2001 13:30:16 +0000
Subject: RE: [PHP-DEV] Security?
Groups: php.dev php.doc 
Request: Send a blank email to php-dev+get-58879@lists.php.net to get a copy of this message
> > I also think that PHP5.0 since we are breaking 
> language compat,
> > perhaps we should turn off register_globals by default?  I 
> just see to
> > many chances for fscking up things big time when using that
> > functionality....
> 
> I still don't agree on this particular point.  All this does is limit
> where data can come from.

And also prevent namespace clashes, eg a GET/POST variable named the
same
as session variables. Turning register_globals off would probably
prevent
a lot of head scratching for peeps who've not come across this issue
before.

-- 
Richard Heyes


Thread (11 messages)

« previous php.dev (#58879) next »