Re: Packages accessing super globals
| From: | Ian P. Christian | Date: | Wed, 18 May 2005 21:41:10 +0000 |
| Subject: | Re: Packages accessing super globals | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-37735@lists.php.net to get a copy of this message | ||
On Wednesday 18 May 2005 22:28, Sean Coates wrote:
> I was part of this discussion, but I'm left wondering "why?"
>
> For what reason would you like these abstracted?
Pretty much all frameworks I've seen or used will provide wrapper functions
around _GET and _POST vars. ( I know PEAR isn't a framework )
Across lots of packages in PEAR, each package is implementing it's own
functions to filter request variables, remove javascript, html, whatever.
This code is no doubt duplicated in many areas of PEAR. With each developer
creating his own, this leaves room for mistakes, and may well result in XSS
in some cases.
Also, GET and POST vars will only be set when working with HTTP, abstracting
this out would allow for other methods of dealing with packages.
In my application framework, I have functions to get the GET and POST
variables, allowing raw access, javascript filtered access, and HTML stripped
access, if PEAR provided this functionality is some way, then all packages
could use these functions to get 'safe' variables. This would avoid code
duplication, reduce the risk of security issues arising in packages using
this method, and possibly allow developers to plug-in request filters.
Kind Regards,
--
Ian P. Christian ~ http://pookey.co.uk
Attachment: [application/pgp-signature]
Attachment: [application/pgp-signature]