The way runProcessor() works now, I would say no.
You’re using the $_POST value only if the $scriptProperties value is not set, but in the processor, the $_POST value will be used if it exists, overriding what you send in the array(). That may change, however.
To make it work as you expect, you could set each $_POST value after each getOption() call.
-
☆ A M B ☆
- 3,112 Posts
ah...
I understand now.
thx.
Rico
Genius is one percent inspiration and ninety-nine percent perspiration.
Thomas A. Edison
MODx is great, but knowing how to use it well makes it perfect!
www.virtudraft.com
Security, security, security! |
Indonesian MODx Forum |
MODx Revo's cheatsheets |
MODx Evo's cheatsheets
Author of
Easy 2 Gallery 1.4.x,
PHPTidy,
spieFeed,
FileDownload R,
Upload To Users CMP,
Inherit Template TV,
LexRating,
ExerPlan,
Lingua,
virtuNewsletter,
Grid Class Key,
SmartTag,
prevNext
Maintainter/contributor of
Babel
Because it's hard to follow all topics on the forum, PING ME ON TWITTER
@_goldsky if you need my help.
-
☆ A M B ☆
- 3,112 Posts
wow...
Is that secure?
Don’t you think you should sanitize the $_GET first before merging it into $scriptProperties?
Rico
Genius is one percent inspiration and ninety-nine percent perspiration.
Thomas A. Edison
MODx is great, but knowing how to use it well makes it perfect!
www.virtudraft.com
Security, security, security! |
Indonesian MODx Forum |
MODx Revo's cheatsheets |
MODx Evo's cheatsheets
Author of
Easy 2 Gallery 1.4.x,
PHPTidy,
spieFeed,
FileDownload R,
Upload To Users CMP,
Inherit Template TV,
LexRating,
ExerPlan,
Lingua,
virtuNewsletter,
Grid Class Key,
SmartTag,
prevNext
Maintainter/contributor of
Babel
Because it's hard to follow all topics on the forum, PING ME ON TWITTER
@_goldsky if you need my help.
Quote from: goldsky at Dec 15, 2010, 07:41 PM
wow...
Is that secure?
Don’t you think you should sanitize the $_GET first before merging it into $scriptProperties?
In the new version, the GPC variables are not used at all.
-
☆ A M B ☆
- 3,112 Posts
I’m reading it.
But in
here, the $_GET parameter is merged plainly.
Or is there any sanitizing afterward?
Rico
Genius is one percent inspiration and ninety-nine percent perspiration.
Thomas A. Edison
MODx is great, but knowing how to use it well makes it perfect!
www.virtudraft.com
Security, security, security! |
Indonesian MODx Forum |
MODx Revo's cheatsheets |
MODx Evo's cheatsheets
Author of
Easy 2 Gallery 1.4.x,
PHPTidy,
spieFeed,
FileDownload R,
Upload To Users CMP,
Inherit Template TV,
LexRating,
ExerPlan,
Lingua,
virtuNewsletter,
Grid Class Key,
SmartTag,
prevNext
Maintainter/contributor of
Babel
Because it's hard to follow all topics on the forum, PING ME ON TWITTER
@_goldsky if you need my help.
Quote from: goldsky at Dec 15, 2010, 08:42 PM
I’m reading it.
But in here, the $_GET parameter is merged plainly.
Or is there any sanitizing afterward?
The minus sign at the left means those line are removed in the commit.