Re: Adding validate_var_array()/validate_input_array() to which version?

From: Date: Mon, 01 Aug 2016 22:12:06 +0000
Subject: Re: Adding validate_var_array()/validate_input_array() to which version?
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-94783@lists.php.net to get a copy of this message
On Mon, Aug 1, 2016 at 5:23 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > We have filter_var_array()/filter_input_array() currently. They are > designed as filter functions. i.e. They convert offending elements to > NULL/FALSE. Therefore, it's difficult to validate and see if inputs > are valid with specified specifications. > > https://github.com/php/php-src/pull/2048 > > This patch adds true validation functions > - validate_var_array() - Almost the same as filter_var_array() except > it returns scalar FALSE on validation failure(s), instead of filtered > array. > - validate_input_array() - Almost the same as filter_input_array() > except it returns scalar FALSE on validation failure(s), instead of > filtered array. > > > These functions are handy for input validation that stops script > execution upon invalid(attacker's) inputs. > > Question is which version should I target for? > It's simple enough patch to be merged to 7.1. IMO. > > Comments are appreciated! > > Regards, Raising Exception would be prefered. Any comment raising exception? ExceptionFilterValidate wouldn't cause much BC, IMO. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#94783) next »