note 72150 added to function.getenv
| From: | roland at mxchange dot org | Date: | Thu, 04 Jan 2007 18:29:04 +0000 |
| Subject: | note 72150 added to function.getenv | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-121302@lists.php.net to get a copy of this message | ||
You need also to know that $_SERVER['SERVER_NAME'] and surely
$_SERVER['PHP_SELF'] are fakeable by sending wrong HTTP headers (hint: "Host:"
will become SERVER_NAME in your PHP scripts). For PHP_SELF you may want to use SCRIPT_NAME instead.
You may want to use this little code to continue using PHP_SELF:
$_SERVER['PHP_SELF'] = $_SERVER['SCRIPT_NAME']; $PHP_SELF =
$_SERVER['PHP_SELF']
The last one is for people who cannot switch "register_global" off.
There is now "secure" replacement for SERVER_NAME available. Sometimes SERVER_ADDR (which
not fakeable) might be handy but in some situations not. If you need a valid entry in SERVER_NAME
validate it with a regular expressions. See regexlib.com for such expressions.
----
Server IP: 212.124.37.9
Probable Submitter: 87.122.65.151
----
Manual Page -- http://www.php.net/manual/en/function.getenv.php
Edit -- https://master.php.net/note/edit/72150
Del: integrated -- https://master.php.net/note/delete/72150/integrated
Del: useless -- https://master.php.net/note/delete/72150/useless
Del: bad code -- https://master.php.net/note/delete/72150/bad+code
Del: spam -- https://master.php.net/note/delete/72150/spam
Del: non-english -- https://master.php.net/note/delete/72150/non-english
Del: in docs -- https://master.php.net/note/delete/72150/in+docs
Del: other reasons-- https://master.php.net/note/delete/72150
Reject -- https://master.php.net/note/reject/72150
Search -- https://master.php.net/manage/user-notes.php