cvs: phpdoc /en/chapters security.xml

From: Date: Fri, 16 May 2003 21:52:58 +0000
Subject: cvs: phpdoc /en/chapters security.xml
Groups: php.doc 
Request: Send a blank email to phpdoc+get-969353549@lists.php.net to get a copy of this message
alindeman Fri May 16 17:52:58 2003 EDT Modified files: /phpdoc/en/chapters security.xml Log: bit o' grammar/spelling Index: phpdoc/en/chapters/security.xml diff -u phpdoc/en/chapters/security.xml:1.53 phpdoc/en/chapters/security.xml:1.54 --- phpdoc/en/chapters/security.xml:1.53 Fri May 16 17:45:36 2003 +++ phpdoc/en/chapters/security.xml Fri May 16 17:52:58 2003 @@ -1,5 +1,5 @@ <?xml version="1.0" encoding="iso-8859-1"?> -<!-- $Revision: 1.53 $ --> +<!-- $Revision: 1.54 $ --> <chapter id="security"> <title>Security</title> @@ -1035,9 +1035,9 @@ <para> When on, register_globals will inject (poison) your scripts will all sorts of variables, like request variables from html forms. This - coupled with the fact that PHP doesn't require variable initializion + coupled with the fact that PHP doesn't require variable initialization means writing insecure code is that much easier. It was a difficult - decision but the PHP community decided to disable this directive by + decision, but the PHP community decided to disable this directive by default. When on, people use variables yet really don't know for sure where they come from and can only assume. Internal variables that are defined in the script itself get mixed up with request data sent by @@ -1069,7 +1069,7 @@ <para> When register_globals = on, our logic above may be compromised. When off, <varname>$authorized</varname> can't be set via request so it'll - be okay although it really is good general programming practice to + be fine, although it really is generally a good programming practice to initialize variables first. For example, in our example above we might have first done <literal>$authorized = false</literal>. Doing this first means our above code would work with register_globals on or off as

« previous php.doc (#969353549) next »