note 43198 added to faq.html
| From: | ppmm at wuxinan dot net | Date: | Sun, 13 Jun 2004 20:11:54 +0000 |
| Subject: | note 43198 added to faq.html | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-71019@lists.php.net to get a copy of this message | ||
3. How do I create arrays in a HTML <form>?
The feature is nice in the sense of simplifying programming. However, this does have side-effect.
Look at this URL below:
http://www.php.net/source.php?url[]=/index.php
As a common viewpoint, exposing the absolute filesystem path in the webpage is always a bad thing. I
reported this problem at bugs.php.net a few days before and I get a response saying "it's
up to programmers". I think it's fair, however, webmaster should really learn to check the
variables at the beginning of the script. In the above case, the PHP script should at least check
like this:
if (!is_string(url)) die("with some error message");
As what I experienced, many PHP-based websites have this problem. I would think a perfect solution
is that PHP does not do this automatic parsing, and when a PHP script expects an array to be posted,
they would do something like
parse_http_array($_GET, "url");
only after this point, $_GET['url']) exists. Before this statement, only
$_GET['url[]'] is available. Well, I am kind of too demanding I guess, but what I really
intended to say is that webmaster should know this problem.
----
Manual Page -- http://www.php.net/manual/en/faq.html.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+43198
Delete -- http://master.php.net/manage/user-notes.php?action=delete+43198&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+43198&report=yes
Search -- http://master.php.net/manage/user-notes.php