note 32810 deleted from function.get-defined-vars by danbrown
| From: | danbrown@php.net | Date: | Fri, 06 Feb 2009 00:53:31 +0000 |
| Subject: | note 32810 deleted from function.get-defined-vars by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-150284@lists.php.net to get a copy of this message | ||
Note Submitter: biyectivo at hotmail dot com
----
Thankfully, get_defined_vars() does NOT return variables which are assigned during an include()
call. This would be a big security hole. For example:
//---------------------------------------------------------
include("foo.php");
$var1 = "Hi";
$vars = get_defined_vars();
$ks = array_keys($vars);
for ($i=0;$i<sizeof($ks);$i++)
{
echo $ks[$i]." --> ".$vars[$ks[$i]]."< br >";
}
//---------------------------------------------------------
will return all server variables, then
var1 --> Hi
but will NOT return
pwd --> MyPassword
even if inside foo.php there is a line stating
$pwd = "MyPassword";