Re: U

From: Date: Mon, 07 Jan 2008 18:09:46 +0000
Subject: Re: U
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.internals 
Request: Send a blank email to internals+get-34587@lists.php.net to get a copy of this message
On Jan 6, 2008 5:06 AM, Stefan Esser <stefan.esser@sektioneins.de> wrote: > Hello Daniel, > > It may be off-topic for the initial post, but I disagree > > wholeheartedly with the above statement, Stefan. There are > > innumerable reasons where $_REQUEST would be much more economic than > > writing out all conditions for $_POST, $_GET, $_SESSION, $_COOKIE.... > > > it doesn't matter if you disagree with my statement, because that is > just another personal opinion. It is a known fact that using $_REQUEST > usually introduces security holes in applications. > There is always $_COOKIE merged into it, which overwrites $_GET and > $_POST. That means I just need to infect your browser with a cookie and > have delayed cross site forgeries all over the place... Believe me, I'm not saying you're wrong, because in 99% (figurative, of course) of the production environments, $_REQUEST is a horrible idea. However, my opinion is just that there is a time and place for it, and it shouldn't be written off completely. For the record, I don't use it myself (save for scripts I write to generate random number lists on my local dev box), it just isn't fair to dismiss it with prejudice. -- Daniel P. Brown [Phone Numbers Go Here!] [They're Hidden From View!] If at first you don't succeed, stick to what you know best so that you can make enough money to pay someone else to do it for you.

« previous php.internals (#34587) next »