note 23991 added to security.registerglobals

From: Date: Sat, 03 Aug 2002 01:24:28 +0000
Subject: note 23991 added to security.registerglobals
Groups: php.notes 
Request: Send a blank email to php-notes+get-34168@lists.php.net to get a copy of this message
Hrm, it seems to me a safer thing to do would be to functionize the above -and provide an argument-. function import($var) { if(isset($HTTP_GET_VARS[$var])) { $$var = $HTTP_GET_VARS[$var]; print "$var in get"; } else if(isset($HTTP_POST_VARS[$var])) { $$var = $HTTP_POST_VARS[$var]; print "$var in post"; } } I'm 99% sure this will work, once I add $GLOBALS[] in the appropriate places (I'm a bit new at this here PHP stuff ;) This way, you can explicitly import only the variables you need, when you need them. Of course there's the usual caveats about content checking etc, but I think this will go a long way to help. -- http://www.php.net/manual/en/security.registerglobals.php http://master.php.net/manage/user-notes.php?action=edit+23991 http://master.php.net/manage/user-notes.php?action=delete+23991 http://master.php.net/manage/user-notes.php?action=reject+23991

« previous php.notes (#34168) next »