note 72150 added to function.getenv

From: Date: Thu, 04 Jan 2007 18:29:04 +0000
Subject: note 72150 added to function.getenv
Groups: php.notes 
Request: Send a blank email to php-notes+get-121302@lists.php.net to get a copy of this message
You need also to know that $_SERVER['SERVER_NAME'] and surely $_SERVER['PHP_SELF'] are fakeable by sending wrong HTTP headers (hint: "Host:" will become SERVER_NAME in your PHP scripts). For PHP_SELF you may want to use SCRIPT_NAME instead. You may want to use this little code to continue using PHP_SELF: $_SERVER['PHP_SELF'] = $_SERVER['SCRIPT_NAME']; $PHP_SELF = $_SERVER['PHP_SELF'] The last one is for people who cannot switch "register_global" off. There is now "secure" replacement for SERVER_NAME available. Sometimes SERVER_ADDR (which not fakeable) might be handy but in some situations not. If you need a valid entry in SERVER_NAME validate it with a regular expressions. See regexlib.com for such expressions. ---- Server IP: 212.124.37.9 Probable Submitter: 87.122.65.151 ---- Manual Page -- http://www.php.net/manual/en/function.getenv.php Edit -- https://master.php.net/note/edit/72150 Del: integrated -- https://master.php.net/note/delete/72150/integrated Del: useless -- https://master.php.net/note/delete/72150/useless Del: bad code -- https://master.php.net/note/delete/72150/bad+code Del: spam -- https://master.php.net/note/delete/72150/spam Del: non-english -- https://master.php.net/note/delete/72150/non-english Del: in docs -- https://master.php.net/note/delete/72150/in+docs Del: other reasons-- https://master.php.net/note/delete/72150 Reject -- https://master.php.net/note/reject/72150 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#121302) next »