Re: Input Validation of $_SESSION values

From: Date: Thu, 06 Nov 2003 05:19:39 +0000
Subject: Re: Input Validation of $_SESSION values
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-168673@lists.php.net to get a copy of this message
--- Pablo Gosse <gossep@unbc.ca> wrote: > It's obviously best practice to rigorously check and validate all input > coming via $_GET or $_POST, but what about $_SESSION values? Session data can be considered safe, but there are of course caveats. It is not possible for the user to manipulate session data at all, whereas GET, POST, and cookie data comes directly from the user. That is the major difference. Of course, if you blindly store client data in a session, you now have tainted session data. So, it all depends on your application. Hope that helps. Chris ===== My Blog http://shiflett.org/ HTTP Developer's Handbook http://httphandbook.org/ RAMP Training Courses http://www.nyphp.org/ramp

« previous php.general (#168673) next »