#33688 [Opn->Csd]: Promoting possible insecure coding practices

From: Date: Thu, 14 Jul 2005 10:18:42 +0000
Subject: #33688 [Opn->Csd]: Promoting possible insecure coding practices
References: 1  Groups: php.doc 
Request: Send a blank email to phpdoc+get-969369117@lists.php.net to get a copy of this message
ID: 33688 Updated by: vrana@php.net Reported By: sesser@php.net -Status: Open +Status: Closed Bug Type: Documentation problem PHP Version: Irrelevant New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. "Consider explode() to set one cookie with multiple names and values. It is not recommended to use serialize() for this purpose, because it can result in security holes." Previous Comments: ------------------------------------------------------------------------ [2005-07-13 23:54:49] sesser@php.net Description: ------------ In the setcookie() description there is the following paragraph: Cookies names can be set as array names and will be available to your PHP scripts as arrays but separate cookies are stored on the users system. Consider explode() or serialize() to set one cookie with multiple names and values. This should be fixed according to the example below... Reproduce code: --------------- --- Expected result: ---------------- Cookies names can be set as array names and will be available to your PHP scripts as arrays but separate cookies are stored on the users system. Consider explode() to set one cookie with multiple names and values. It is not recommended to use serialize() for this purpose, because it can result in security holes. Actual result: -------------- Cookies names can be set as array names and will be available to your PHP scripts as arrays but separate cookies are stored on the users system. Consider explode() or serialize() to set one cookie with multiple names and values. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=33688&edit=1

« previous php.doc (#969369117) next »