note 122843 deleted from reserved.variables.get by peehaa

From: Date: Sun, 28 Apr 2019 11:00:17 +0000
Subject: note 122843 deleted from reserved.variables.get by peehaa
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-210853@lists.php.net to get a copy of this message
Note Submitter: DimeCadmium ---- Do NOT, as some people have recommended, "pre-clean" $_GET (or $_POST) at the top of your pages. First, you will almost certainly not clean it properly (since the method of cleaning depends on how it's being used - i.e. is it being output within HTML, or in a text/plain page, or maybe in an image or PDF or email? Or better yet is it going to a database?). But much worse, it will introduce subtle issues and will almost certainly lead to things being double escaped. Take it from someone who is getting paid for hours and hours of work fixing an old application which took this approach (calling mysqli_real_escape_string on "everything"* in $_POST/$_GET). Please don't do it. (*: it actually misses some stuff - it doesn't escape anything in an array in $_GET i.e. ?foo[]=some+bad+SQL+injection+here ! If you're going to do it at least do it right... you'll need a recursive function and you'll need to do it for $_POST, $_GET, and $_REQUEST, at the very least. Probably $_COOKIE as well. You'll also need to be sure you don't use php://input or similar anywhere... or, just, be sure you don't take any kind of input from any other source...)

« previous php.notes (#210853) next »