Re: How to test
| From: | Justin French | Date: | Thu, 08 Aug 2002 11:56:40 +0000 |
| Subject: | Re: How to test | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-111631@lists.php.net to get a copy of this message | ||
on 08/08/02 8:46 PM, Bas Jobsen (bas@startpunt.cc) wrote:
> Well, okay. But when foo.pho is on www.foo.com/foo.php
> I can place the <form
> action="http://www.foo.com/foo.php"
> method="post">
> on every place i want. And i want to know for sure, that the form on
> http://www.foo.com/form.php is used
Well, that's not what you asked :)
HTTP_REFERER is not always set, so you can't rely on it.
As far as making sure the form is POSTed, if the vars are not in the $_POST
array, then it wasn't POSTed.
I haven't thought this through entirely, but you can set a hidden field in
the form with a unique random string, and also set that string as a session
variable.
When you validate the form input, IF the vars are in the POST array, AND
there is a session ID, AND the random string passed in the form matches the
string in your $_SESSION array, then I guess you can be around 99% sure that
it was done kosher. But the session COULD be spoofed. Nothing is absolute.
I haven't really though about it...
I'm sure if you search the archives there'll be heaps of solutions... I
remember seeing a few, but didn't pay attention...
Justin French
> Op donderdag 08 augustus 2002 12:25, schreef Justin French:
>> If you're using PHP >= 4.1.1, pull the vars straight out of the POST super
>> global array.
>>
>> <form action="foo.php" method="post">
>> <input type="text" name="foo">
>> </form>
>>
>> <?
>> //foo.php
>> echo $_POST['foo'];
>> ?>
>>
>> There's also GET, COOKIE, SESSION, ENV, and a few more -- have a read here:
>> http://www.php.net/manual/en/language.variables.predefined.php
>>
>>
>> Justin French
>>
>> on 08/08/02 7:31 PM, Bas Jobsen (bas@startpunt.cc) wrote:
>>> Hello,
>>>
>>> How can i test if a post request realy came from the right form?
>>> Now i have:
>>>
>>>
>>> if(!strstr($HTTP_SERVER_VARS['HTTP_REFERER'],$HTTP_SERVER_VARS['SERVER_NA
>>> ME'])
>>>
>>> || $HTTP_SERVER_VARS['REQUEST_METHOD']!='POST')exit;
>>>
>>> But this goes wrong soon as HTTP_REFERER isn't set.
>>>
>>> Thanks,
>>>
>>> Bas