parent
480b969fd1
commit
92ca57d644
@ -1,19 +0,0 @@ |
|||||||
Please note that main.inc.php, which should be called by index.php, does |
|
||||||
the following: |
|
||||||
|
|
||||||
unset($_REQUEST); |
|
||||||
unset($_GET); |
|
||||||
unset($_POST); |
|
||||||
|
|
||||||
So, you must use \tts\safer_io::sanitize(....); to get those input vars!!! |
|
||||||
That method, returns an array of fields, html, and errors, I'll break that down: |
|
||||||
fields are the raw or result of the filter_input function, |
|
||||||
html is passed an function to escape or sanitize the HTML output in someway (so use it for any output on views), |
|
||||||
errors will have an count > 0 if validation rules were not meet. |
|
||||||
|
|
||||||
Alternatively; use the built in PHP filter_input function. |
|
||||||
|
|
||||||
Likewise, if not using sanitize... then for all HTML output use |
|
||||||
\tts\safer_io::h(...) to escape it. |
|
||||||
|
|
||||||
|
|
||||||
Loading…
Reference in new issue