RE: [PHP] extract($_POST)
| From: | John W. Holmes | Date: | Wed, 23 Oct 2002 23:41:03 +0000 |
| Subject: | RE: [PHP] extract($_POST) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-121179@lists.php.net to get a copy of this message | ||
Yeah, just use $_POST['name']. Why waste space assigning it to another
variable $name. If you get used to using it this way, it'll be better.
Plus, you'll be able to tell throughout your code what is from the user,
POST/GET/COOKIE, and what is your own variables.
Idealy, you should be validating everything from the user before you use
it anywhere. If this is a name, you should be making sure it's just
letters, dashes, apostrophes, and maybe a period. I usually assign
everything into an $input[] array after it's validated.
$input['name'] = validate("name",$_POST['name']);
Then, I know that later in my code, I should only be using the $input
array in any SQL statements or echos to HTML code, because I know it's
been validated.
Hope that helps.
---John Holmes...
> -----Original Message-----
> From: ed@home.homes2see.com [mailto:ed@home.homes2see.com]
> Sent: Wednesday, October 23, 2002 1:41 PM
> To: 1LT John W. Holmes
> Subject: Re: [PHP] extract($_POST)
>
>
> So, just to be on the safe'er' side I should extract via
>
> $name = $_POST['name'];
>
> or just use $_POST['name'] within the script when I need it's value
from
> the form.
>
> There is some light at the end of the tunnel now. I'll just ignore
those
> that keep saying extract($_POST) is the exact same as $_POST['var'] :)
>
> Thanks for all your help,
>
> Ed
>
> On Wed, 23 Oct 2002, 1LT John W. Holmes wrote:
>
> > > So what you are actually saying is that the switchover to
> > > register_globals turned off and using $_POST or $_GET retrieval is
> only as
> > > secure as older php methods where you could just pass the variable
by
> > > name? If each process can only get the variables that were passed
to
> it
> > > why would it matter which method you used?
> >
> > If you have a form where you ask for someones name, and you use
> > $_POST['name'] to refer to the value, you know that the value in
that
> > variable came from that text box and, this is the key, no other
> variables
> > passed to the script will be used.
> >
> > Say I modify your above form on my own server and add additional
fields
> or
> > connect directly to your web server and send raw POST data. If you
are
> just
> > referring to $_POST['name'], then it doesn't matter what extra
> information I
> > send, your script will never use it.
> >
> > However, if you now extract($_POST), all of those variables I just
sent
> you
> > are created for your script. So later on, when you check for
> > isset($administrator), you may be using the $administrator variable
I
> passed
> > to you in POST, instead of the one created in your script.
> >
> > ---John Holmes...
> >