Re: Re: PHP 4.3.3RC3 Released

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: Re: PHP 4.3.3RC3 Released
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-3935@lists.php.net to get a copy of this message
Right, and in the end this should be done on a per-site basis through the input filtering mechanism I added to PHP5 a while ago. -Rasmus On Thu, 14 Aug 2003, Ilia Alshanetsky wrote: > First of all this discussion bares to relevance to the 4.3.3 release as sqlite > is NOT part of this release. Secondly this is just plain silly. PHP is not > and is not responsible for validating input. If the user chooses not to and > consequently leaves their scripts vulnreable to SQL injection it is their > fault and their fault alone. > Ability to chain queries is an extremely useful feature that most database > systems support (even MySQL as of version 4.0). To cripple or disable such > functionality would be absolute idiocy not to mention break backwards > compatibility to older versions where this was possible. Adding more run-time > directives (as suggested by Hartmut Holzgraefe ) is a bad idea as it makes > writing portable code extremely difficult as each system may have a > drastically different behavior due to an ini option. > > Ilia > > > -- > PHP Internals - PHP Runtime Development Mailing List > To unsubscribe, visit: http://www.php.net/unsub.php >

« previous php.internals (#3935) next »