Re: Re: languages and PHP
| From: | Edward Vermillion | Date: | Fri, 28 Sep 2007 18:21:54 +0000 |
| Subject: | Re: Re: languages and PHP | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-262565@lists.php.net to get a copy of this message | ||
On Sep 28, 2007, at 1:05 PM, Per Jessen wrote:
Edward Vermillion wrote:But that was my point. Your way, your app may disintegrate at some uncontrolled point. At least if your checking/validating your input then you can take control of the situation and insure the "survival of your application". Otherwise who knows where it will break and what it will mean when it does. And just because the community is closed, don't drop your guard on basic security practices. You don't control what comes into your site, you can only react to it. EdI pretty much gave up on the thread when I got the reply along the lines of "if it breaks something it's their problem, not mine".Ed, your question was a good one, but so was my answer. In my case, I don't cater to an open community, but to a closed one. If you're not authenticated, you're not getting anywhere to start with. If you somehow manage to bypass that, and attempt to submit data I don't expect, my priority is the survival of my application, nothing else.