note 33985 deleted from function.import-request-variables by sniper
| From: | sniper@php.net | Date: | Sat, 23 Aug 2003 00:07:01 +0000 |
| Subject: | note 33985 deleted from function.import-request-variables by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-54893@lists.php.net to get a copy of this message | ||
Note Submitter: nospam at thenerdshow dot calm
----
Thanks for all the suggestions. This is how I import variables when I want to keep the same name,
without a prefix, yet still maintain the security of only allowing certain variables into the scope.
This one accepts input from post, get and cookie while setting any unsubmitted variables to NULL,
preventing errors. Just one issue: You can use if ($email) to check for null but if
($email=="") doesn't seem to work. If you prefer to do your checks that way then
change NULL to "" in this example:
$expected=array(
'name', // Only accept these variables from a submit!
'email',
'favorite_color'
); foreach ($expected as $formvar)
$$formvar = (isset($_REQUEST[$formvar]))?$_REQUEST[$formvar]:NULL;