RE: [PHP] extract($_POST)

From: Date: Wed, 23 Oct 2002 03:20:13 +0000
Subject: RE: [PHP] extract($_POST)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-121026@lists.php.net to get a copy of this message
> Ok then, what about this scenario... > > Let's for hypothetical puprposes say I have a simple form and that form > that passes 40 variables manually entered in text fields to another script > and there are 100 people submitting that script at the exact same moment > what keeps someone from getting another persons values from the server > using the $_POST['var'] retrieval method? That's not possible. I don't know how to explain it technically, but when you submit the form, your data is passed to an instance of the processing script and the script runs. Even if a dozen instances are all running at once, each only operates on the data that was passed to it by the user pressing submit. > What would be the most secure way to keep this from happening? This is > what I'm facing at this very moment. I'm now sitting on the verge of a > very large project where there could be potentially 5,000 or more people > using this form at any given moment. Cookies have been eliminated > as a storage option as approximately one third of the end users > would not be allowing cookies onto their system. With this many potential > end users it wouldn't be out of the question that 2 or more people would > be submitting data through the form at the exact same time. What are you "storing"?? ---John Holmes...

« previous php.general (#121026) next »