Re: Array security?
| From: | Chris Adams | Date: | Thu, 29 Jun 2000 02:44:29 +0000 |
| Subject: | Re: Array security? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-3725@lists.php.net to get a copy of this message | ||
> I have been passing arrays in forms using hidden types and using the implode
> and explode functions in php. The question I have is been asking myself is
> there a better way and more secure way to pass these arrays because all you
> have to do is view the source of the page to see all the values etc. What I
> want to do is make it to where people can't see these values or anything of
> that nature. I'm at the intermediate level of php programming so I would
> think that there has to be a better and more secure way of passing arrays
> between forms.
Yes. Use sessions. The session library will send a single cookie to the user and use that cookie to
keep track of a set of data (aka session variables) used with that user. The big advantage to
sessions is that the user can't alter the data stored on the server, so a session variable like
$UserID or $AccessLevel is safe while a regular get, post or cookie variable is not. Another minor
advantage is that you don't need to pass huge amounts of information between pages, so you
reduce
the data sent back and forth between the client. If we're talking about large data structures,
this
could be a non-trivial savings.
One other alternative if you need the arrays but they aren't unique to a given user would be to
stuff everything into local storage somewhere and use that. PHP doesn't have a built-in
application
variable library but it wouldn't be that hard to make one. I've used a special library I
wrote for
caching in a couple apps; it automatically implements a timeout and keeps track of data by URL. In a
couple cases, I have a function which will return a fairly large and complex data structure (which
takes a non-trivial amount of CPU time and database queries to build). If it's already in the
cache,
it just calls unserialize() and returns the cached value. If not, it generates it and uses
serialize() to cache it.
Chris