Re: Re: PHP taint support: first results
| From: | (Wietse Venema) | Date: | Fri, 05 Oct 2007 18:25:50 +0000 |
| Subject: | Re: Re: PHP taint support: first results | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-32656@lists.php.net to get a copy of this message | ||
Rasmus Lerdorf:
> Consider very common (abbreviated) code like this:
>
> $user_data = $_REQUEST['data'];
> switch($output_format) {
Question: where is the output format feature documented?
Once I know the output format is not HTML, then I know
that applying HTML-style restrictions is not appropriate.
I did search around but came up empty handed.
Wietse