PHP's new input_filter does not read $_GET or $_POST arrays

前端 未结 6 1500
温柔的废话
温柔的废话 2020-12-16 00:28

In PHP 5.2 there was a nice security function added called \"input_filter\", so instead of saying:

$name = $_GET[\'name\'];

you can now say

6条回答
  •  孤街浪徒
    2020-12-16 01:01

    You could manually force it to read the arrays again by using filter_var and filter_var_array

    $name = filter_var ( $_GET['name'], FILTER_SANITIZE_STRING );
    

提交回复
热议问题