RE: [PHP-DEV] Security Issues
| From: | Brian Tanner | Date: | Thu, 26 Jul 2001 18:16:44 +0000 |
| Subject: | RE: [PHP-DEV] Security Issues | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61076@lists.php.net to get a copy of this message | ||
>>accept_parameters($user_string); // or something similar
If PHP is going to break a bunch of scripts, they would probably just shut
register_globals off.
This would require people to do:
$user_string=$HTTP_POST_VARS["user_string"];
This accomplishes the same thing as your example, and doesn't introduce any
new syntax... I don't really see the advantage of the "accept_parameters"
idea.
-Brian Tanner