Re: Proporsal for cascadable general HTTP input handler

From: Date: Sun, 09 Dec 2001 22:53:23 +0000
Subject: Re: Proporsal for cascadable general HTTP input handler
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-72963@lists.php.net to get a copy of this message
The input could be an array pointer for the splited and url decoded input by POST/GET/Cookie. The output could be an array including result or return code of the handler. These handlers should be activated in php_treat_data before php_register_variable_safe(). An example is php_mbstr_encoding_handler() in ext/mbstring.c. The argument of php_mbstr_encoding_handler() is, static void php_mbstr_encoding_handler(zval *arg, char *res, char *separator TSRMLS_DC) But, the array pointer should be better to simplify the handler. On Sun, 09 Dec 2001 20:21:02 +0200 Zeev Suraski <zeev@zend.com> wrote: > What would be the input/output of these input handlers? > > Zeev > > At 07:19 09/12/2001, Rui Hirokawa wrote: > > >Hi, > > > >I propose a new idea for HTTP input handler to improve security and > >multibyte encoding support. > > > >Currently, user input by POST/GET/Cookie is treated by > >internal function php_treat_variables(). > > > >Some security related work to prevent some security attack > >is preformed in PHP script by htmlspecialchars() and regex(). > > > >And multibyte encoding detection and translation which is necessary > >for multibyte enable Web application is implemented by > >override php_treat_variables(). > > > >My idea is to introduce some general input filter/handler > >for php_treat_variables(). > > > >It is a similar concept as output buffering handler. > > > >For example, if a user defined > > > >input_handler = http_input_check,mb_filter > > > >in php.ini, user defined security check handler and > >multibyte encoding translation are perfomed. > > > >Generally, http input check for secure transaction is really > >hard work and some programers might make some critical mistake. > >And PHP script with http input check is usually hard to read. > > > >If we can use http input handler, we can implemnt separately > >http input check and Web application. > > > >-- > >----------------------------------------------------- > >Rui Hirokawa <rui_hirokawa@ybb.ne.jp> > > <hirokawa@php.net> > > > > > >-- > >PHP Development Mailing List <http://www.php.net/> > >To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > >For additional commands, e-mail: php-dev-help@lists.php.net > >To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net -- ----------------------------------------------------- Rui Hirokawa <rui_hirokawa@ybb.ne.jp> <hirokawa@php.net>

« previous php.dev (#72963) next »