RE: [PHP] extract($_POST)

From: Date: Wed, 23 Oct 2002 23:41:03 +0000
Subject: RE: [PHP] extract($_POST)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-121179@lists.php.net to get a copy of this message
Yeah, just use $_POST['name']. Why waste space assigning it to another variable $name. If you get used to using it this way, it'll be better. Plus, you'll be able to tell throughout your code what is from the user, POST/GET/COOKIE, and what is your own variables. Idealy, you should be validating everything from the user before you use it anywhere. If this is a name, you should be making sure it's just letters, dashes, apostrophes, and maybe a period. I usually assign everything into an $input[] array after it's validated. $input['name'] = validate("name",$_POST['name']); Then, I know that later in my code, I should only be using the $input array in any SQL statements or echos to HTML code, because I know it's been validated. Hope that helps. ---John Holmes... > -----Original Message----- > From: ed@home.homes2see.com [mailto:ed@home.homes2see.com] > Sent: Wednesday, October 23, 2002 1:41 PM > To: 1LT John W. Holmes > Subject: Re: [PHP] extract($_POST) > > > So, just to be on the safe'er' side I should extract via > > $name = $_POST['name']; > > or just use $_POST['name'] within the script when I need it's value from > the form. > > There is some light at the end of the tunnel now. I'll just ignore those > that keep saying extract($_POST) is the exact same as $_POST['var'] :) > > Thanks for all your help, > > Ed > > On Wed, 23 Oct 2002, 1LT John W. Holmes wrote: > > > > So what you are actually saying is that the switchover to > > > register_globals turned off and using $_POST or $_GET retrieval is > only as > > > secure as older php methods where you could just pass the variable by > > > name? If each process can only get the variables that were passed to > it > > > why would it matter which method you used? > > > > If you have a form where you ask for someones name, and you use > > $_POST['name'] to refer to the value, you know that the value in that > > variable came from that text box and, this is the key, no other > variables > > passed to the script will be used. > > > > Say I modify your above form on my own server and add additional fields > or > > connect directly to your web server and send raw POST data. If you are > just > > referring to $_POST['name'], then it doesn't matter what extra > information I > > send, your script will never use it. > > > > However, if you now extract($_POST), all of those variables I just sent > you > > are created for your script. So later on, when you check for > > isset($administrator), you may be using the $administrator variable I > passed > > to you in POST, instead of the one created in your script. > > > > ---John Holmes... > >

« previous php.general (#121179) next »