Re: [RFC] Name issue - is_literal/is_trusted
| From: | Craig Francis | Date: | Thu, 24 Jun 2021 00:26:12 +0000 |
| Subject: | Re: [RFC] Name issue - is_literal/is_trusted | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-115089@lists.php.net to get a copy of this message | ||
On Thu, 24 Jun 2021 at 1:09 am, Bruce Weirdan <weirdan@gmail.com> wrote:
> > - String + int concatenation isn't an injection risk.
>
> I think this demonstrates it very well could be:
> https://externals.io/message/114988#115038
That’s the developer choosing to use a variable, and it’s no different than
the developer using a library to add the value via proper quoting/escaping.
Craig