RE: [PHP] extract($_POST)
| From: | John W. Holmes | Date: | Wed, 23 Oct 2002 03:20:13 +0000 |
| Subject: | RE: [PHP] extract($_POST) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-121026@lists.php.net to get a copy of this message | ||
> Ok then, what about this scenario...
>
> Let's for hypothetical puprposes say I have a simple form and that
form
> that passes 40 variables manually entered in text fields to another
script
> and there are 100 people submitting that script at the exact same
moment
> what keeps someone from getting another persons values from the server
> using the $_POST['var'] retrieval method?
That's not possible. I don't know how to explain it technically, but
when you submit the form, your data is passed to an instance of the
processing script and the script runs. Even if a dozen instances are all
running at once, each only operates on the data that was passed to it by
the user pressing submit.
> What would be the most secure way to keep this from happening? This is
> what I'm facing at this very moment. I'm now sitting on the verge of a
> very large project where there could be potentially 5,000 or more
people
> using this form at any given moment. Cookies have been eliminated
> as a storage option as approximately one third of the end users
> would not be allowing cookies onto their system. With this many
potential
> end users it wouldn't be out of the question that 2 or more people
would
> be submitting data through the form at the exact same time.
What are you "storing"??
---John Holmes...