Re: PHP 5.1

From: Date: Fri, 04 Feb 2005 10:08:49 +0000
Subject: Re: PHP 5.1
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-14641@lists.php.net to get a copy of this message
On Friday 04 February 2005 10:00, Rasmus Lerdorf wrote: > It comes down the fact that every single piece of data you get from GET, > POST, Cookie and some Server variables *must* be at the very least be > passed through htmlentities or striptags before you can display any part > of them. Exactly, those are very simple rules.. People need to learn that every var they send to the browser needs to be htmlescaped. Every var that makes it into the database query string needs to be escaped according to that database standard. If we can make this easier I'd say go for it. But "polluting" PHP's input seem to me like the wrong way to go about it. Even worse it can be activated by an ini option that would make writing portable PHP code more difficult thus repeating magic_* failure. Edin

« previous php.internals (#14641) next »