Reply to Re: sort of argument verifier

Your name:

Reply:


Posted by Peter Fox on 10/24/00 11:40

Following on from julian_m's message. . .
>Let's say I've a page which is called with arguments a, b and c
>
>test.php?a=val_a&b=val_b&c=val_c
>
>but, i don't want to allow anyone to modify either val_a, val_b or
>val_c
>
>I thought it would be a good idea, to add another argument which could
>combines (through some algorithm) val_a, val_b and val_c, and check it
>every time the page is called.
>
>I was wondering whether any of this exists already. I don't want to
>reinvent the wheel, you know...
>
>regards - jm
>
Whilst normally it would be an excellent idea to abstract the issue as
you have done, the nature of the values and the context will help us
here to give you a more informed choice.

In the abstract:
* 'checksum'
* pack and obfuscate
* store a,b,c in array in session indexed by random key
* validate the input _as is_ and chuck out ones you don't like and if
somebody has altered &a=red to &a=pink well then that's up to them
either it works or it doesn't.
* change your page calling scheme/data model




--
PETER FOX Not the same since the exam marking business failed
peterfox@eminent.demon.co.uk.not.this.bit.no.html
2 Tees Close, Witham, Essex.
Gravity beer in Essex <http://www.eminent.demon.co.uk>

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация