note 73387 added to reserved.variables

From: Date: Wed, 21 Feb 2007 07:56:14 +0000
Subject: note 73387 added to reserved.variables
Groups: php.notes 
Request: Send a blank email to php-notes+get-123623@lists.php.net to get a copy of this message
u7 at h4ck3d dot eu discourages from the use of $_REQUEST[]. For the precise reasons this user has for their opinion, I would strongly recommend its usage - it forces you to program safely, whilst simultaneously letting you (1) test your script against hacks easier (providing you're not already using a plug-in for your browser that allows you to manipulate "post" data with ease, it's a blessing to be able to test via "get") (2) and allowing you flexible use, such as either changing your mind about the method later with little to no tweaking, or by simply allowing both $_POST[] and $_GET[]. I was concerned reading u7's post, because I think the advice is dangerous to give... it implies $_POST[] or $_GET[] are safer. Yet if someone truly wants to hack your site, the method is (in 99 of 100 cases, with the 1 case being the get-method's limit on the amount of data that can be transferred) entirely irrelevant, and that makes it a dangerous assumption. Safety is using mysql_real_escape_string, using htmlspecialchars, using urlencode, using addslashes, and the whole myriad of other escaping functions at your disposal. Check your data rigorously. Don't rely on a method. ---- Server IP: 217.13.201.10 Probable Submitter: 84.46.119.45 ---- Manual Page -- http://www.php.net/manual/en/reserved.variables.php Edit -- https://master.php.net/note/edit/73387 Del: integrated -- https://master.php.net/note/delete/73387/integrated Del: useless -- https://master.php.net/note/delete/73387/useless Del: bad code -- https://master.php.net/note/delete/73387/bad+code Del: spam -- https://master.php.net/note/delete/73387/spam Del: non-english -- https://master.php.net/note/delete/73387/non-english Del: in docs -- https://master.php.net/note/delete/73387/in+docs Del: other reasons-- https://master.php.net/note/delete/73387 Reject -- https://master.php.net/note/reject/73387 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#123623) next »