RE: [PHP-DEV] Security Issues

From: Date: Fri, 27 Jul 2001 07:21:22 +0000
Subject: RE: [PHP-DEV] Security Issues
Groups: php.dev 
Request: Send a blank email to php-dev+get-61166@lists.php.net to get a copy of this message
> >>accept_parameters($user_string); // or something similar > register_globals off. > $user_string=$HTTP_POST_VARS["user_string"]; > > This accomplishes the same thing as your example, and doesn't > introduce any new syntax... I don't really see the advantage of the > "accept_parameters" idea. Well, the programmer doesn't need to know if it was introduced by POST or GET or whatever, and will be made to think about what parameters he/she is accepting... thereby making him aware of the security issues. Plus, it looks better :-) (yeah I know, subjective...) Cheerio, Marc.

« previous php.dev (#61166) next »