Re: Input Validation of $_SESSION values
| From: | Chris Shiflett | Date: | Thu, 06 Nov 2003 05:19:39 +0000 |
| Subject: | Re: Input Validation of $_SESSION values | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-168673@lists.php.net to get a copy of this message | ||
--- Pablo Gosse <gossep@unbc.ca> wrote:
> It's obviously best practice to rigorously check and validate all input
> coming via $_GET or $_POST, but what about $_SESSION values?
Session data can be considered safe, but there are of course caveats. It
is not possible for the user to manipulate session data at all, whereas
GET, POST, and cookie data comes directly from the user. That is the major
difference. Of course, if you blindly store client data in a session, you
now have tainted session data. So, it all depends on your application.
Hope that helps.
Chris
=====
My Blog
http://shiflett.org/
HTTP Developer's Handbook
http://httphandbook.org/
RAMP Training Courses
http://www.nyphp.org/ramp