note 42419 deleted from index by nlopess

From: Date: Mon, 17 May 2004 14:53:40 +0000
Subject: note 42419 deleted from index by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-69718@lists.php.net to get a copy of this message
Note Submitter: vrrivaro@yahoo.com ---- The register_globals funtion is a security hazard. I have found a way to get its extreme advantages securely, while also documenting your code. To use my method, you would begin your code with: <? $parameters = array( "requestMethod1" => array("variable1"=>"default") ,"requestMethod2" => array("variable2"=>"default") ); require_once("includes/parameters.inc.php"); ?> For example: <? parameters = array( "'_GET" => array ("page"=>"aprobeCreditCard","itemsPerPg"=>5) ,"'_COOKIE" => array("user"=>"johnDoe", "passwd"=>"invalid") ,"'_POST" => array("user" => "not used", "passwd"=>"who cares") ); require_once('includes/parameters.inc.php'); ?> Thus you have right in front of you wich parameters are expected by your script, what their default values are and where they are expected from. Order is important. The user and password are espected to come from a cookie or the post method, with the post method being prevalent (the log in info from login forms should prevail from what's stored in a cookie) except for defualt values, which come from the cookie (where they are defined first). Allow me a few side notes. Please note that I know that it is an extremely bad idea to pass passwords around in cookies like this (especially when dealing with credit cards) but I am just making a point. As for the way I format my array definitions, IMHO this is better because it allows for (1) easylly seeing at first sight ehich lines actually have the ommas and which don't and (2) easily adding or removing items from the list without having to chase around the lines for commas. Last, I keep all my include files together in the includes directory, and I name the all *.inc.php. The parameters.inc.php file should be: <?php //////////////////////////////////////////////////////////////// // parameters.inc.php //////////////////////////////////////////////////////////////// // Repeat this for each especified method foreach ($parameters as $method) { // Define the variables with their specified result value foreach ($method as $variable=>$defaultValue) { $variable = $defaultValue; }; // Extract the variables from the specified method if provided extract($method,EXTR_IF_EXITS); } ?> That's just my grain of sand. Hope this is of use to anyone. Thank you, Victor Rafael Rivarola Soerensen (My last name is Rivarola, not Soerensen).

« previous php.notes (#69718) next »