Re: PHP 5.1
| From: | Edin Kadribasic | Date: | Fri, 04 Feb 2005 10:08:49 +0000 |
| Subject: | Re: PHP 5.1 | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-14641@lists.php.net to get a copy of this message | ||
On Friday 04 February 2005 10:00, Rasmus Lerdorf wrote:
> It comes down the fact that every single piece of data you get from GET,
> POST, Cookie and some Server variables *must* be at the very least be
> passed through htmlentities or striptags before you can display any part
> of them.
Exactly, those are very simple rules.. People need to learn that every var
they send to the browser needs to be htmlescaped. Every var that makes it
into the database query string needs to be escaped according to that database
standard.
If we can make this easier I'd say go for it. But "polluting" PHP's input seem
to me like the wrong way to go about it. Even worse it can be activated by an
ini option that would make writing portable PHP code more difficult thus
repeating magic_* failure.
Edin