note 32791 added to function.include

From: Date: Fri, 06 Jun 2003 21:42:23 +0000
Subject: note 32791 added to function.include
Groups: php.notes 
Request: Send a blank email to php-notes+get-49917@lists.php.net to get a copy of this message
For users that absolutely want to include($_GET["something"]). As said above by many peaple, it's a very bad idea because of the security issues it brings. A simple way to correct this (even for novice users) is to implement a switch, referring to all your scripts : (That supposes that you already know the script names you will include...) Exemple: ======== switch ($_GET["pagetoinclude"]) { case "tomatoes": include("tomatoes.php"); break; case "apples": include("apple.php"); break; default: include("error.php?msg=Bad-Parameter"); } End of exemple ============ This way, you won't have any bad surprises with kiddies playing with arguments. (Hope this helps) ---- Manual Page -- http://www.php.net/manual/en/function.include.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32791 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32791&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32791&report=yes

« previous php.notes (#49917) next »