note 52283 added to language.variables.predefined
| From: | sendoshin | Date: | Wed, 27 Apr 2005 00:58:13 +0000 |
| Subject: | note 52283 added to language.variables.predefined | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-88601@lists.php.net to get a copy of this message | ||
There is one way to safely execute PHP code files without running the risk of compromising your own
code. A prior note pointed out that the code being evaluated would still have access to globals
using the global keyword. While this is a valid point, there's one other approach to be looked
at - one which actually gives you much more ability than just unsetting some variable references.
It's known as code parsing.
The specifics would be different and much more complex in a deployed site, but here's an
extremely strip-down example of how to restrict access to global variables:
<?php
while ($x = stristr ($code_to_eval, "global")) {
$temp = substr ($code_to_eval, 1, $x-1);
$temp .= substr ($code_to_eval, stristr ($code_to_eval, ";", $x) + 1);
$code_to_eval = $temp;
}
$ret_val = eval ($code_to_eval);
?>
Of course, that's just a rudimentary example, and a deployment version would have much more
checking involved, but parsing the file before you eval it lets you remove any code you don't
want to let run, thus making it as safe as your parsing rules.
----
Manual Page -- http://www.php.net/manual/en/language.variables.predefined.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+52283
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+52283&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+52283&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+52283&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+52283&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+52283&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+52283&report=yes
Search -- http://master.php.net/manage/user-notes.php