Re: How to test

From: Date: Thu, 08 Aug 2002 11:56:40 +0000
Subject: Re: How to test
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-111631@lists.php.net to get a copy of this message
on 08/08/02 8:46 PM, Bas Jobsen (bas@startpunt.cc) wrote: > Well, okay. But when foo.pho is on www.foo.com/foo.php > I can place the <form > action="http://www.foo.com/foo.php" > method="post"> > on every place i want. And i want to know for sure, that the form on > http://www.foo.com/form.php is used Well, that's not what you asked :) HTTP_REFERER is not always set, so you can't rely on it. As far as making sure the form is POSTed, if the vars are not in the $_POST array, then it wasn't POSTed. I haven't thought this through entirely, but you can set a hidden field in the form with a unique random string, and also set that string as a session variable. When you validate the form input, IF the vars are in the POST array, AND there is a session ID, AND the random string passed in the form matches the string in your $_SESSION array, then I guess you can be around 99% sure that it was done kosher. But the session COULD be spoofed. Nothing is absolute. I haven't really though about it... I'm sure if you search the archives there'll be heaps of solutions... I remember seeing a few, but didn't pay attention... Justin French > Op donderdag 08 augustus 2002 12:25, schreef Justin French: >> If you're using PHP >= 4.1.1, pull the vars straight out of the POST super >> global array. >> >> <form action="foo.php" method="post"> >> <input type="text" name="foo"> >> </form> >> >> <? >> //foo.php >> echo $_POST['foo']; >> ?> >> >> There's also GET, COOKIE, SESSION, ENV, and a few more -- have a read here: >> http://www.php.net/manual/en/language.variables.predefined.php >> >> >> Justin French >> >> on 08/08/02 7:31 PM, Bas Jobsen (bas@startpunt.cc) wrote: >>> Hello, >>> >>> How can i test if a post request realy came from the right form? >>> Now i have: >>> >>> >>> if(!strstr($HTTP_SERVER_VARS['HTTP_REFERER'],$HTTP_SERVER_VARS['SERVER_NA >>> ME']) >>> >>> || $HTTP_SERVER_VARS['REQUEST_METHOD']!='POST')exit; >>> >>> But this goes wrong soon as HTTP_REFERER isn't set. >>> >>> Thanks, >>> >>> Bas

« previous php.general (#111631) next »