Re: PHP 6.0 Wishlist

From: Date: Sat, 13 Aug 2005 19:49:56 +0000
Subject: Re: PHP 6.0 Wishlist
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-17986@lists.php.net to get a copy of this message
But then everybody will just start using $_RAW_GET instead of $_GET. What will that solve?
This was one of my concerns. $_RAW_* is easy to grep for, though. Sure, it can still be abused, but it'll be a lot easier to see WHERE it's being abused. Currently, a grep for $_GET will return a large number of false positives when searching for XSS (because it's the most legit way of finding data entry points). S

« previous php.internals (#17986) next »