QuickForm Controller idea.
| From: | Nathan Lenz | Date: | Fri, 01 Oct 2004 20:26:56 +0000 |
| Subject: | QuickForm Controller idea. | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-33605@lists.php.net to get a copy of this message | ||
I'm not sure if this is the correct place to suggest this idea,
please let me know if I should talk about this somewhere else.
The QuickForm Controller class uses $_SESSION['_myformname_container']
as a container to pass data between pages of the form.
A project I'm working on right now needs to accept credit card data in
one of the steps. However I don't want to ever store the credit card
numbers in plain text.
Here are three ideas I have been thinking about:
1. Extend HTML_QuickForm_Action for each of the actions doing the
encryption/decryption in each of the actions. (Best solution?)
2. Modify the QuickForm Controller class so that it can
encrypt/decrypt everything (or just specific fields) put into the
session using one of the PEAR Crypt packages.
3. Use session_set_save_handler() to create functions which encrypt
the session data before it is written to the file. I did Google for
encrypted php sessions and found at least one piece of code that
encrypts sessions stored in a MySQL database. This would encrypt ALL
the data in my session which is probably overkill.
I would appreciate suggestions/feedback.
Thank you,
--Nathan
--
Nathan Lenz
nathan.lenz /at/ gmail.com