note 78895 deleted from function.assert-options by tularis

From: Date: Thu, 01 Nov 2007 09:12:13 +0000
Subject: note 78895 deleted from function.assert-options by tularis
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-131903@lists.php.net to get a copy of this message
Note Submitter: roland dot illig at gmx dot de ---- Beware of using assert for input validation. At least, be sure you have read and understood the documentation of assert(string). <?php // Warning: this code does not do what it looks like. $name = $_REQUEST["name"]; assert($name); // check that name is given print "Hello, " . htmlspecialchars($name) . "\n"; ?> The above code doesn't check that a name is given, but _evaluates_ the name. So when you send "system('id')" as your name in an HTTP request, the server will probably output something interesting. Instead, use the following code: <?php assert($name !== ""); ?> But beware of the string comparison operator. It sometimes also doesn't do what you would expect.

« previous php.notes (#131903) next »