note 61073 added to security.globals

From: Date: Wed, 25 Jan 2006 01:04:08 +0000
Subject: note 61073 added to security.globals
Groups: php.notes 
Request: Send a blank email to php-notes+get-102398@lists.php.net to get a copy of this message
Regarding mike at uwmike dot com's snippet, it appears that calling this code causes $GLOBALS to become recursive within itself with a quick check to get_defined_vars(). A better version of this code without using $GLOBALS with the desired result is: <?php if (@ini_get('register_globals')) { foreach ($_REQUEST as $key => $value) { unset($$key); } } ?> While more effective, this method still leaves non-$_REQUEST vars, such as $_SERVER vars, set. One could remove these by creating an array of vars to be removed. Consider: <?php if (@ini_get('register_globals')) { $remove_vars = $_REQUEST + $_SERVER; foreach ($remove_vars as $key => $value) { unset($$key); } } ?> ---- Server IP: 216.194.113.175 Probable Submitter: 24.151.24.6 ---- Manual Page -- http://www.php.net/manual/en/security.globals.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+61073 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+61073&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+61073&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+61073&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+61073&report=yes&reason=useless Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+61073&report=yes&reason=non-english Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+61073&report=yes&reason=already+in+docs Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+61073&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+61073&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#102398) next »