Re: Secure eval();

From: Date: Tue, 21 May 2002 15:09:22 +0000
Subject: Re: Secure eval();
References: 1 2 3 4 5  Groups: php.general 
Request: Send a blank email to php-general+get-98606@lists.php.net to get a copy of this message
Why don't you just do it all in your query?? SELECT (({table1.field1} * {table2.field2}) + {table3.field3}) FROM table1, table2, table3 WHERE ... ---John Holmes... ----- Original Message ----- From: "Chris Boget" <chris@wild.net> To: "1LT John W. Holmes" <holmes072000@charter.net>; "PHP General" <php-general@lists.php.net> Sent: Tuesday, May 21, 2002 10:53 AM Subject: Re: [PHP] Secure eval(); > > Are you sure you have to run it through eval()? It sounds like you're > > creating a query. Couldn't you just create the query dynamically, then put > > it in a mysql_query() function? (or whatever DB you're using) Then, even if > > they try some kung fu on you, it'll just result in a bad query, not some > > rogue code being executed. > > Try some kung fu? Never heard it put like that before. :P > > I am kind of creating a query. The equation is going to look something like > this: > > (({table1.field1} * {table2.field2}) + {table3.field3}) > > Then I'm going to get the values in those fields and parse the above as if they > were macros (which, in a sense, they are). That could yield something like: > > ((8 * 5) + 3) > > and it is that equation that I'm going to need to eval. So I don't think I'll be able > to do this in a query. > > Chris >

« previous php.general (#98606) next »