Re: Adding validate_var_array()/validate_input_array() to which version?
| From: | Yasuo Ohgaki | Date: | Mon, 01 Aug 2016 22:12:06 +0000 |
| Subject: | Re: Adding validate_var_array()/validate_input_array() to which version? | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94783@lists.php.net to get a copy of this message | ||
On Mon, Aug 1, 2016 at 5:23 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> We have filter_var_array()/filter_input_array() currently. They are
> designed as filter functions. i.e. They convert offending elements to
> NULL/FALSE. Therefore, it's difficult to validate and see if inputs
> are valid with specified specifications.
>
> https://github.com/php/php-src/pull/2048
>
> This patch adds true validation functions
> - validate_var_array() - Almost the same as filter_var_array() except
> it returns scalar FALSE on validation failure(s), instead of filtered
> array.
> - validate_input_array() - Almost the same as filter_input_array()
> except it returns scalar FALSE on validation failure(s), instead of
> filtered array.
>
>
> These functions are handy for input validation that stops script
> execution upon invalid(attacker's) inputs.
>
> Question is which version should I target for?
> It's simple enough patch to be merged to 7.1. IMO.
>
> Comments are appreciated!
>
> Regards,
Raising Exception would be prefered.
Any comment raising exception? ExceptionFilterValidate wouldn't
cause much BC, IMO.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net