Re: Re: The new $_GET/POST/ENV (was: Re: [PHP-CVS] cvs: php4 / NEWS...)
| From: | Cynic | Date: | Wed, 08 Aug 2001 18:25:47 +0000 |
| Subject: | Re: Re: The new $_GET/POST/ENV (was: Re: [PHP-CVS] cvs: php4 / NEWS...) | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-62597@lists.php.net to get a copy of this message | ||
At 20:14 8/8/2001, Jani Taskinen wrote the following:
--------------------------------------------------------------
>On Wed, 8 Aug 2001, Cynic wrote:
>
>>How about $_DONT_TOUCH_THIS ? :)
>>Seriously though, I vote for $_REQUEST. After all, it contains
>>data which is (generally) tied to one particular request...
>
>This reminds me that should the $_FILES be included in this
>data too? As it's also something you shouldn't trust and
>it's also coming from the user.
>
>--Jani
Yeah. And $_SESSION too.
cynic@mail.cz
-------------
And the eyes of them both were opened and they saw that their files
were world readable and writable, so they chmoded 600 their files.
- Book of Installation chapt 3 sec 7