note 23090 deleted from security.registerglobals by philip
| From: | philip@php.net | Date: | Mon, 02 Dec 2002 20:14:16 +0000 |
| Subject: | note 23090 deleted from security.registerglobals by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-40270@lists.php.net to get a copy of this message | ||
If you have globals turned on.. but use important variables like $_server["php_auth_user"]
instead of $php_auth_user varible.
Would this be effectively secure enough to use this PHP authentication?
This assumes all other variables used in a document do not matter or are validated.