[dokuwiki] Re: Fwd: DokuWiki - Full path disclosure

  • From: Andreas Gohr <andi@xxxxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Sun, 24 Jun 2012 14:10:59 +0200

>> I don't know if it is really better, but we could introduce some
>> wrapper around _POST, _REQUEST, _GET
>
> Now that you're suggesting it as well, I guess I go ahead and
> add it...

done. We now have a $INPUT which gives easy, type safe access to these
vars. Check 
https://github.com/splitbrain/dokuwiki/commit/89177306a2278255d6a2203b5fff4a839183d3cd
for an overview how to use it.

Everyone holding back, now it's time to go through
https://docs.google.com/spreadsheet/ccc?key=0AsrTBbNk9K0udFpRTzZNUG5Ga3ZnNVFYSEtLZ2NwakE
and update the codebase to make use of the new wrapper.

Andi

-- 
splitbrain.org
-- 
DokuWiki mailing list - more info at
http://www.dokuwiki.org/mailinglist

Other related posts: