Re: [PHP4BETA] Is autoregister of HTTP_STATE_VARS possible?
| From: | Shane Burrell | Date: | Tue, 07 Mar 2000 21:03:35 +0000 |
| Subject: | Re: [PHP4BETA] Is autoregister of HTTP_STATE_VARS possible? | ||
| References: | 1 2 3 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-11722@lists.php.net to get a copy of this message | ||
On Tue, 07 Mar 2000, Andrei Zmievski wrote:
> Automatically registering everything that's in $HTTP_STATE_VARS[] on
> register_globals=off might be possible. I need more feedback from people
> to see whether this is such a good idea. As far as your question, I
> don't quite understand what you mean. The best way is not obvious to me.
>
From a readibilty standpoint using $HTTP_*_VARS instead of letting the vars be
in the global scope makes sense. I assume that's why the register_globals
option was added and $HTTP_*_VARS are there. We have code that uses the old
method of global vars to reference data.
For example developer A used a $HTTP_GET_VAR called $Loan_ID on the query
string. Later developer B registered a session var called $Loan_ID. Both
developers use the global var called $Loan_ID. The result was that in some
circumstances $Loan_ID was stomped on and it was very hard to determine the
difference between the Session Loan_ID and the GET Loan_ID.
To fix this problem it makes sense to us to turn off Globals and require the
the HTTP_*_VARS be used when accessing them.
Now back to my question, have I got it all wrong? Should we be trying to
migrate to a code base that works with register_globals=off?