note 37365 deleted from security.registerglobals by didou
| From: | didou@php.net | Date: | Wed, 12 Nov 2003 08:53:36 +0000 |
| Subject: | note 37365 deleted from security.registerglobals by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-60293@lists.php.net to get a copy of this message | ||
Note Submitter:
----
Everybody who codes like --Example 15-14. Example misuse with register_globals = on-- should be
punished for it anyway, it is a dumb example and it is just plain stupid allowing anybody to mess
with your variables in that fashion. Always check for valid values before using variables unless the
value doesn't matter!!
So why not point out this problem to everybody and turn it on again, now I have to worry about tons
and tons of code I wrote and may have to add extra functions just to get the variables working
again.
Please remember that the _GET variable wasn't even available when I started working with PHP.
Now I am almost forced to use it just to be on the safe side. I guess backwards compatibility
doesn't mean anything to or exists in PHP.
The function about two posts higher is a good one though, as it will facilitate all dummies -who
shouldn't even make any kind of script, leave it to the profs- with their "Ow I
hadn't thought of that." solution... ...Learn to make a proper design first!!!