RE: [PHP] $_REQUEST???
| From: | Philip Olson | Date: | Wed, 10 Jul 2002 05:30:42 +0000 |
| Subject: | RE: [PHP] $_REQUEST??? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-106668@lists.php.net to get a copy of this message | ||
> I'm not sure if it's true or not, but someone said all data coming
> through _POST and _COOKIES is filtered - making it safer than pulling
> the raw data from variables.
Filtered? Nothing is filtered. Only you know what data
the users should be sending, validate accordingly and
assume all request data is unsafe. The only "filter" I
see here is how the data is seperated by type, ex. only
GET is in $_GET.
Regards,
Philip Olson