note 78895 deleted from function.assert-options by tularis
| From: | tularis@php.net | Date: | Thu, 01 Nov 2007 09:12:13 +0000 |
| Subject: | note 78895 deleted from function.assert-options by tularis | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-131903@lists.php.net to get a copy of this message | ||
Note Submitter: roland dot illig at gmx dot de
----
Beware of using assert for input validation. At least, be sure you have read and understood the
documentation of assert(string).
<?php
// Warning: this code does not do what it looks like.
$name = $_REQUEST["name"];
assert($name); // check that name is given
print "Hello, " . htmlspecialchars($name) . "\n";
?>
The above code doesn't check that a name is given, but _evaluates_ the name. So when you send
"system('id')" as your name in an HTTP request, the server will probably output
something interesting.
Instead, use the following code:
<?php
assert($name !== "");
?>
But beware of the string comparison operator. It sometimes also doesn't do what you would
expect.