Re: extract($_POST)
| From: | 1LT John W. Holmes | Date: | Wed, 23 Oct 2002 18:27:53 +0000 |
| Subject: | Re: extract($_POST) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-121150@lists.php.net to get a copy of this message | ||
> So what you are actually saying is that the switchover to
> register_globals turned off and using $_POST or $_GET retrieval is only as
> secure as older php methods where you could just pass the variable by
> name? If each process can only get the variables that were passed to it
> why would it matter which method you used?
If you have a form where you ask for someones name, and you use
$_POST['name'] to refer to the value, you know that the value in that
variable came from that text box and, this is the key, no other variables
passed to the script will be used.
Say I modify your above form on my own server and add additional fields or
connect directly to your web server and send raw POST data. If you are just
referring to $_POST['name'], then it doesn't matter what extra information I
send, your script will never use it.
However, if you now extract($_POST), all of those variables I just sent you
are created for your script. So later on, when you check for
isset($administrator), you may be using the $administrator variable I passed
to you in POST, instead of the one created in your script.
---John Holmes...