note 81805 added to function.extract
| From: | HayleyWatson at osu1 dot php dot net | Date: | Thu, 13 Mar 2008 23:18:00 +0000 |
| Subject: | note 81805 added to function.extract | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-137044@lists.php.net to get a copy of this message | ||
Dan O'Donnell's suggestion needs a third requirement to work as described:
c) No other variables are defined - especially variables that contain potentially sensitive
information.
Without that condition the difference between extract() and assigning variables by hand (and the
resulting security implications) should be obvious.
The only valid security step there is (b) - but you should be doing that anyway.
----
Server IP: 202.89.58.1
Probable Submitter: 60.234.168.92
----
Manual Page -- http://www.php.net/manual/en/function.extract.php
Edit -- https://master.php.net/note/edit/81805
Del: integrated -- https://master.php.net/note/delete/81805/integrated
Del: useless -- https://master.php.net/note/delete/81805/useless
Del: bad code -- https://master.php.net/note/delete/81805/bad+code
Del: spam -- https://master.php.net/note/delete/81805/spam
Del: non-english -- https://master.php.net/note/delete/81805/non-english
Del: in docs -- https://master.php.net/note/delete/81805/in+docs
Del: other reasons-- https://master.php.net/note/delete/81805
Reject -- https://master.php.net/note/reject/81805
Search -- https://master.php.net/manage/user-notes.php