Re: Solution for html source <img="gif_script.php?var..."> ?

From: Date: Fri, 28 Jul 2000 06:59:35 +0000
Subject: Re: Solution for html source <img="gif_script.php?var..."> ?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-8719@lists.php.net to get a copy of this message
> I'm afraid this will not solve my problem, maybe I did not explain it properly. > I do not have any problems getting the script to work, it's the html source > that bothers me. > It will still show <IMG SRC=image.php?Msg=Foo+Bar&Size=12> if the client > browser saves the picture/ views the source. > And that is something I'm not too happy about, it invites people to play > with the img script through their browser, > setting font sizes to 68 and that sort of stuff.... So store these parameters somewhere else and just pass in a pointer. ie. <IMG SRC=image.php?ID=48373278937> and then in image.php use this id to look up the actual parameters in your data store. Just like a session. In fact, you could simply use the session mechanism. Alternatively, you could encode it. Like this: $args=urlencode(base64_encode('Msg=Foo+Bar&Size=12')); Then pass it in the img src tag like this: <IMG SRC=image.php?args=<?echo $args?>> Inside image.php you would do: parse_str(base64_decode($args)); And now your $Msg and $Size variables are magically set, but the URL the user sees it: image.php?args=TXNnPUZvbytCYXImU2l6ZT0xMg%3D%3D This isn't super secure of course. Somebody might figure out that this is a urlencoded base64 encoded string and reverse engineer it. But the casual browser is not going to be able to figure this out. And if they just random change stuff it won't work. -Rasmus

« previous php.general (#8719) next »