in reply to CGI OO 'param' vs. hash
Where your SafeNumberParam function might look like:# Regular CGI my $quantity = $q->param('quantity'); # Tainted # "Fancy" CGI of your own construction my $quantity = $q->SafeNumberParam('quantity'); # De-tainted
sub SafeNumberParam { my ($self) = shift; my ($param) = @_; my ($number) = $self->param($param) =~ /^(\d+)/; return $number; }
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
(Ovid) Re(2): CGI OO 'param' vs. hash
by Ovid (Cardinal) on Jul 09, 2001 at 23:16 UTC | |
by legLess (Hermit) on Jul 10, 2001 at 00:06 UTC | |
by Ovid (Cardinal) on Jul 10, 2001 at 00:20 UTC | |
by legLess (Hermit) on Jul 10, 2001 at 00:34 UTC | |
by tye (Sage) on Jul 10, 2001 at 01:34 UTC | |
|
Re: Re: CGI OO 'param' vs. hash
by legLess (Hermit) on Jul 10, 2001 at 00:11 UTC |