RE: [PHP] why values not remembered by php?
| From: | Lars Torben Wilson | Date: | Wed, 23 Aug 2000 02:26:21 +0000 |
| Subject: | RE: [PHP] why values not remembered by php? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-13063@lists.php.net to get a copy of this message | ||
Sonia Tsui writes:
> Lars,
>
> Thank you very much for your explanation. You helped me clear up my
> concepts.
>
> It works when I just encode the variables into URL
> (main.php?start=10&end=15), but I am concerned about the security involved
> here because user can just change the value for the variable get passed in
> the URL. I think hidden variable in a form will be a better way.
As long as you validate your input (i.e. never pass any input directly
to anything, check it all and make sure it's within sane limits etc),
all that'd do would be to screw up their page views. So they'd be
shooting themselves in the foot. (Assuming that there aren't rows in
that db table that certain users shouldn't be allowed to see, which is
another story.)
> <form>
> <input type ="hidden" name="start" value=<?php echo($start);?>>
> </form>
>
> But since form will only be posted if the submit button is clicked. But
> there is no submit button need on my page, so how do I do the hidden
> variable thing? May be I am being unclear here.
>
> ---Sonia
Well, this is exactly as (in)secure as the URL method. Nothing stops
someone from finding out what the hidden fields are (View Source) and
POSTing their own values there.
But if you really want to do it that way, try something like this:
<form>
<input type="hidden" name="start" value="<?php
echo($start);?>">
<input type="hidden" name="end" value="<?php
echo($end);?>">
<input type="submit" name="action" value="Prev">
<input type="submit" name="action" value="Next">
</form>
...and then test for the value of $action in the script. But again,
this doesn't really gain you anything over the URL method. If the
security of the values is important to you, I would strongly suggest
looking into a good session management system. Typically, it would
work by storing the data somewhere, and generating an encrypted key
which is used to index the stored data. The encrypted key is then sent
as a cookie (or passed along in ht URL), and when the page loads the
next time, it gets the cookie/key back and uses it to look up the
stored data. If the key is well-generated, it'll be hard for someone
to guess it and hijack the session. Unless they are eavesdropping on
your connection, or reading your cookies file, or something. But it's
enough security for most things.
Cheers,
Torben
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+