Re: Packages accessing super globals

From: Date: Wed, 18 May 2005 22:59:11 +0000
Subject: Re: Packages accessing super globals
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37738@lists.php.net to get a copy of this message
Ian P. Christian wrote: > Across lots of packages in PEAR, each package is implementing it's own > functions to filter request variables, remove javascript, html, whatever. > This code is no doubt duplicated in many areas of PEAR. With each developer > creating his own, this leaves room for mistakes, and may well result in XSS > in some cases. I think the decision of what should and what shouldn't be filtered, should be left to the package using those variables. However I can see the need for some kind of centralized parameter handling for namespacing parameters, handling alternative inputs and building URL's. For example if I would like to put two paged datasets onto one page, the generated links would need to 1) use differently named parameters. 2) keep the other objects parameters intact. That kind of centralized handling of mapping HTTP request to package parameters would probably also allow a lot easier implementation of those popular "nice URL's" where parameters are part of the URL path, not the query string. I also wouldn't worry about performance. If well implemented the overhead should be only a bit more than 1 functioncall per parameter which really isn't all that much. -------------------- Ants Aasma

« previous php.pear.dev (#37738) next »