We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 26931
    • 2,314 Posts
    Hi there,

    i’m using a Ditto config file and would like to know what’s the best practice to make it secure
    e.g.
    <?php
    $myOrder = 'createdon DESC';
    if ($_GET['order'] == 'down') {
      $myOrder = 'createdon DESC';
    }
    if ($_GET['order'] == 'up') {
      $myOrder = 'createdon ASC';
    }
    $orderBy = array('parsed'=>array(),'custom'=>array(),'unparsed'=>$myOrder);
    ?>


    or
    <?php
    $myOrder = 'createdon DESC';
    if ($_GET['order'] == 'down') {
      $myOrder = 'createdon DESC';
    }
    elseif ($_GET['order'] == 'up') {
      $myOrder = 'createdon ASC';
    }
    else $myOrder = '';
    
    $orderBy = array('parsed'=>array(),'custom'=>array(),'unparsed'=>$myOrder);
    ?>


    should i use preg_replace for this?

    http://wiki.modxcms.com/index.php/Snippet_security_flaws

    thanks, j
      • 1122
      • 209 Posts
      Something like this should be short, clear, secure, and extensible
      <?php
      $xlat = array(
          'down' => 'createdon DESC',
          'up' => 'createdon ASC',
          '...' => '...',
      );
      
      // set default
      $myOrder = 'createdon DESC';
      
      // possibly fetch it from url
      if (isset($_GET['order']) && isset($xlat[$_GET['order']])) {
          $myOrder = $xlat[$_GET['order']];
      }
      
      // go ahead and make use of your carefully verified $myOrder...
      ?>
      
        • 26931
        • 2,314 Posts
        thanks alik!! smiley