note 42419 added to index
| From: | vrrivaro at yahoo dot com | Date: | Sun, 16 May 2004 01:51:06 +0000 |
| Subject: | note 42419 added to index | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-69657@lists.php.net to get a copy of this message | ||
The register_globals funtion is a security hazard. I have found a way to get its extreme advantages
securely, while also documenting your code.
To use my method, you would begin your code with:
<?
$parameters = array(
"requestMethod1" => array("variable1"=>"default")
,"requestMethod2" => array("variable2"=>"default")
);
require_once("includes/parameters.inc.php");
?>
For example:
<?
parameters = array(
"'_GET" => array
("page"=>"aprobeCreditCard","itemsPerPg"=>5)
,"'_COOKIE" => array("user"=>"johnDoe",
"passwd"=>"invalid")
,"'_POST" => array("user" => "not used",
"passwd"=>"who cares")
);
require_once('includes/parameters.inc.php');
?>
Thus you have right in front of you wich parameters are expected by your script, what their default
values are and where they are expected from.
Order is important. The user and password are espected to come from a cookie or the post method,
with the post method being prevalent (the log in info from login forms should prevail from
what's stored in a cookie) except for defualt values, which come from the cookie (where they
are defined first).
Allow me a few side notes. Please note that I know that it is an extremely bad idea to pass
passwords around in cookies like this (especially when dealing with credit cards) but I am just
making a point. As for the way I format my array definitions, IMHO this is better because it allows
for (1) easylly seeing at first sight ehich lines actually have the ommas and which don't and
(2) easily adding or removing items from the list without having to chase around the lines for
commas. Last, I keep all my include files together in the includes directory, and I name the all
*.inc.php.
The parameters.inc.php file should be:
<?php
////////////////////////////////////////////////////////////////
// parameters.inc.php
////////////////////////////////////////////////////////////////
// Repeat this for each especified method
foreach ($parameters as $method) {
// Define the variables with their specified result value
foreach ($method as $variable=>$defaultValue) {
$variable = $defaultValue;
};
// Extract the variables from the specified method if provided
extract($method,EXTR_IF_EXITS);
}
?>
That's just my grain of sand. Hope this is of use to anyone.
Thank you,
Victor Rafael Rivarola Soerensen
(My last name is Rivarola, not Soerensen).
----
Manual Page -- http://www.php.net/manual/en/index.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+42419
Delete -- http://master.php.net/manage/user-notes.php?action=delete+42419&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+42419&report=yes
Search -- http://master.php.net/manage/user-notes.php