Bug #15108 Updated: Server variables to exist globally w/ register_globals = off

From: Date: Fri, 18 Jan 2002 21:52:15 +0000
Subject: Bug #15108 Updated: Server variables to exist globally w/ register_globals = off
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-77478@lists.php.net to get a copy of this message
ID: 15108 Updated by: hholzgra Reported By: philip@cornado.com Old Status: Open Status: Bogus Bug Type: Feature/Change Request Operating System: n/a PHP Version: 4.1.1 New Comment: > But most importantly, this will be useful. no it won't, same security consideration as with the other global registrations Previous Comments: ------------------------------------------------------------------------ [2002-01-18 16:14:25] philip@cornado.com In short, when register_globals = off, server variables would/should continue to register globally. Variables such as: $PHP_SELF, $DOCUMENT_ROOT, $REMOTE_ADDR, etc. As currently they do not. And on a sidenote, the current docs imply that server variables always exist, regardless of setting. Some possible options: a) Create a new config setting, such as register_server_globals or register_predefined_globals b) Make register_globals allow for individual EGPCS settings (default to S) c) Make server variables always exist, like track_vars do now. d) ... This will help ease the register_globals = off transition as well as cause a lot less "4.2.0 BROKE PHP!!!" emails. But most importantly, this will be useful. ------------------------------------------------------------------------ Edit this bug report at http://bugs.php.net/?id=15108&edit=1

« previous php.dev (#77478) next »