Re: PHP 6.0 Wishlist
| From: | Sean Coates | Date: | Sat, 13 Aug 2005 19:49:56 +0000 |
| Subject: | Re: PHP 6.0 Wishlist | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-17986@lists.php.net to get a copy of this message | ||
But then everybody will just start using $_RAW_GET instead of $_GET. What will that solve?This was one of my concerns. $_RAW_* is easy to grep for, though. Sure, it can still be abused, but it'll be a lot easier to see WHERE it's being abused. Currently, a grep for $_GET will return a large number of false positives when searching for XSS (because it's the most legit way of finding data entry points). S