note 122843 deleted from reserved.variables.get by peehaa
| From: | peehaa@php.net | Date: | Sun, 28 Apr 2019 11:00:17 +0000 |
| Subject: | note 122843 deleted from reserved.variables.get by peehaa | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-210853@lists.php.net to get a copy of this message | ||
Note Submitter: DimeCadmium
----
Do NOT, as some people have recommended, "pre-clean" $_GET (or $_POST) at the top of your
pages. First, you will almost certainly not clean it properly (since the method of cleaning depends
on how it's being used - i.e. is it being output within HTML, or in a text/plain page, or maybe
in an image or PDF or email? Or better yet is it going to a database?). But much worse, it will
introduce subtle issues and will almost certainly lead to things being double escaped.
Take it from someone who is getting paid for hours and hours of work fixing an old application which
took this approach (calling mysqli_real_escape_string on "everything"* in $_POST/$_GET).
Please don't do it.
(*: it actually misses some stuff - it doesn't escape anything in an array in $_GET i.e.
?foo[]=some+bad+SQL+injection+here ! If you're going to do it at least do it right...
you'll need a recursive function and you'll need to do it for $_POST, $_GET, and
$_REQUEST, at the very least. Probably $_COOKIE as well. You'll also need to be sure you
don't use php://input or similar anywhere... or, just, be sure you don't take any kind of
input from any other source...)