Re: request data filter
| From: | Zeev Suraski | Date: | Thu, 16 Jan 2003 15:17:44 +0000 |
| Subject: | Re: request data filter | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-93525@lists.php.net to get a copy of this message | ||
At 02:52 16/01/2003, Rasmus Lerdorf wrote:
In trying to implement a security policy I need to pass all user-supplied data (GET/POST/Cookie) through a filter function which implements this security. This isn't all that hard to implement as an extension through new 4.3 treat_data and post_handler hooks, however it gets messy when you throw mbstring into the mix as that extension also uses those hooks. The cleanest way I can think of doing this is to add a function pointer to SAPI for the filtering function that will be run right before the php_register_variable_safe() call. Currently we are always calling php_url_decode() on the data before registering the variable, so I propose that we make php_url_decode() the default that an extension can then override. Anybody see any reason not to make this simple change? Without that I will need to somehow detect whether mbstring is present and then filter the data after it has already been registered by mbstring's treat_data/post_handler hooks. That's a big mess!Sounds good to me. Zeev