Hallo,
ich benutze exec_INSERTquery um Formulareingaben aus einem Frontend-Plugin in die Datenbank zu schreiben.
Besitzt diese Funktion bereits Überprüfungsroutinen zur Datensicherheit (wie im PHP z.B. die Prepared Statements), oder ist man besser damit beraten die eingegebenen Daten mittels PHP auf böse Sonderzeichen und Skripte zu untersuchen?
exec_INSERTquery und Sicherheit
Hallo,
wenn du from, where usw brav trennst bist du schon mal auf der sichereren seite, aber ein Blick auf http://typo3.org/fileadmin/typo3api-4.0.0/de/d07/classt3lib__DB.html#7b17306626fbf95a27cf7c854cfba59a verrät:
string Optional additional WHERE clauses put in the end of the query. NOTICE: You must escape values in this argument with $this->fullQuoteStr() yourself!
Dann noch ein Blick in die TYPO3 Coding Guidelines > http://typo3.org/documentation/document-library/core-documentation/doc_core_cgl/current/view/
GET and POST values
When you take in values from outside through GET and POST you should always use the API functions supplied by TYPO3. They are t3lib_div::_GET(), t3lib_div::_POST(), and t3lib_div::_GP(). These will always deliver you values where quotes are not escaped (thus “clean”). And that means you can consistently pass these values through $GLOBALS['TYPO3_DB']->quoteStr() when building queries.Generally for WHERE clauses
For all WHERE clauses (of UPDATE, DELETE and SELECT) remember rigid usage of $GLOBALS['TYPO3_DB']->quoteStr() / intval() + of course such as t3lib_BEfunc::deleteClause() etc.
lg georg
Der Hinweis auf ein profanes htmlspecialchars() wäre wohl angebrachter gewesen,
wenn es um Sicherheit und Formulareingaben geht. 😉