note 23597 deleted from security.registerglobals by nlopess

From: Date: Sat, 10 Jan 2004 15:56:53 +0000
Subject: note 23597 deleted from security.registerglobals by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-63274@lists.php.net to get a copy of this message
Note Submitter: ---- Having global variables or indeterminate origin was a pain, but like many things people rely on it. In a serious production environment, this should be off (if only I had known this could have been turned off earlier). However many beginners will have learnt to use this facility, so there should be a means to turn it on of off on a per site (or per page) basis. After all the server's security model shouldn't allow php to be running as a user that has serious access to break things anyway. Any perceived breech should only be a flaw in the php sites coding. The responsiblity for fixing this is in the author of site, whom should write better php, putting all code inside classes, so global variables need to be explicity accessed for example. Flaws in C are exactly the same, don't change the compiler, just fix your code.

« previous php.notes (#63274) next »