Proporsal for cascadable general HTTP input handler

From: Date: Sun, 09 Dec 2001 05:19:26 +0000
Subject: Proporsal for cascadable general HTTP input handler
Groups: php.dev 
Request: Send a blank email to php-dev+get-72951@lists.php.net to get a copy of this message
Hi, I propose a new idea for HTTP input handler to improve security and multibyte encoding support. Currently, user input by POST/GET/Cookie is treated by internal function php_treat_variables(). Some security related work to prevent some security attack is preformed in PHP script by htmlspecialchars() and regex(). And multibyte encoding detection and translation which is necessary for multibyte enable Web application is implemented by override php_treat_variables(). My idea is to introduce some general input filter/handler for php_treat_variables(). It is a similar concept as output buffering handler. For example, if a user defined input_handler = http_input_check,mb_filter in php.ini, user defined security check handler and multibyte encoding translation are perfomed. Generally, http input check for secure transaction is really hard work and some programers might make some critical mistake. And PHP script with http input check is usually hard to read. If we can use http input handler, we can implemnt separately http input check and Web application. -- ----------------------------------------------------- Rui Hirokawa <rui_hirokawa@ybb.ne.jp> <hirokawa@php.net>

« previous php.dev (#72951) next »