Re: Undefined Variables

From: Date: Wed, 22 Nov 2000 18:14:27 +0000
Subject: Re: Undefined Variables
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-26687@lists.php.net to get a copy of this message
Hi Maxim: > I am talking about error_repoprting(0) which when inserted at the beginning > of the file avoids these stupid "undefined variable" errors, Undefined variable reporting is a "non-critical style-related warning." These show up when error reporting has level 8 turned on. You can change the default level in the php.ini file. For more info, check the "Error Handling" and "General Configuration Directives" sections of the manual. But, do note, undefined variable errors are FAR from stupid. Nefarious users can hijack variables you don't expressly set. This can happen in any script. Example: if ($Publication) { $Date = date("Ymd"); } if ($Date) { $Pointer = fopen("$Date", "r"); } Usually, that wouldn't be a problem. But, you'll be screwed if some clever nasty person hits your page with this URI: http://www.foo.org/?Date=password.txt They'll be able to get this hypothetical password file. > Will error_reporting(0) also influent some other parser, function, array > errors? Yes. But, if that's not what you want, you have the option to set exactly what kinds of errors get displayed. Again, look at the "Error Handling" section in the manual. Enjoy, --Dan -- PHP scripts that make your job easier http://www.analysisandsolutions.com/code/ SQL Solution | Layout Solution | Form Solution T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y 4015 7 Ave, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409

« previous php.general (#26687) next »