Re: Packages accessing super globals
| From: | Ants Aasma | Date: | Wed, 18 May 2005 22:59:11 +0000 |
| Subject: | Re: Packages accessing super globals | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-37738@lists.php.net to get a copy of this message | ||
Ian P. Christian wrote:
> Across lots of packages in PEAR, each package is implementing it's own
> functions to filter request variables, remove javascript, html, whatever.
> This code is no doubt duplicated in many areas of PEAR. With each developer
> creating his own, this leaves room for mistakes, and may well result in XSS
> in some cases.
I think the decision of what should and what shouldn't be filtered,
should be left to the package using those variables. However I can see
the need for some kind of centralized parameter handling for namespacing
parameters, handling alternative inputs and building URL's.
For example if I would like to put two paged datasets onto one page, the
generated links would need to
1) use differently named parameters.
2) keep the other objects parameters intact.
That kind of centralized handling of mapping HTTP request to package
parameters would probably also allow a lot easier implementation of
those popular "nice URL's" where parameters are part of the URL path,
not the query string.
I also wouldn't worry about performance. If well implemented the
overhead should be only a bit more than 1 functioncall per parameter
which really isn't all that much.
--------------------
Ants Aasma