The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Is this function good?
Here's my edit_comment function, is it good? It's coding in OOP, though I kind of lost my understanding for it, so I'm going to have to reread on it. That's why I'm posting this, and also if it meets 3.5 syntax standards correctly, and if it's secure. This way, I can edit all my mistakes in previous functions I wrote. Any comments are greatly appreciated.
PHP Code:
|
#2
|
||||
|
||||
I'd change the $_REQUEST['do'] to $_POST['do'] so someone can't manipulate the URL and have it submit.
|
#3
|
|||
|
|||
Well I was also going to add permissions to that if statement, would the $_POST['do'] still be needed?
|
#4
|
||||
|
||||
It depends what triggers the function and any other security checks you have, but personally I would use $_POST for doing this.
|
#5
|
||||
|
||||
$_POST can be manipulates as easily as $_GET, so you won't gain much.
|
#6
|
||||
|
||||
i would go with post, at least its checked from which referrer
|
#7
|
|||
|
|||
Okay, then I guess I will change it to post for added security. Is everything else okay, besides that?
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|