Hey Ammar,
Thanx for the feedback.

1) I'm totally with you on the bad use of SESSION. The idea of having one global variable being modified by a number of methods with no type of sync or validation is actually raping all proper development techniques. But i couldn't figure how to do that any other way. For example, i need to know the validation required on every field.Should i place them in a hidden form element and pass them with the form? or perhaps modify the name/id of teh element in a way that i know what is the validation required? I ruled against the first because the urlParams firefox extensions (i'm sure there are other ways) allows you to modify POST and GET variables, so a malicious user could change the validation required. And i ruled against the second idea because maybe the developer wants to pass some _javascript_ through the $extra parameter, and modifying the element id would stop it from working correctly.
I know that turning off register globals prevent users from modifying super global variables, but data integrity is extremely important in this project and the clients' hosting is not yet clear. Maybe it'll be in house with full control on every aspect of the environment, or shared hsoting with only a .htaccess file allowed.

2) Changing the form layout is going to be hell, true. But this works for my current project. So i'm not going to immediatly change it. However this is extremely important if i want to use this class beyond my current project. I'll investigate this further at a later time.

3) PUT??? this is the first time i heard of this method, i'll google it a bit.

4) The widget class is going to evolve into something totally different than what i sent you. I have some -hopefully- neat ideas. but this was a fast roundup that does the minimum accepted lvl for my current project.

5) Filters!!.. now that's a good idea.. i'll RTFM it a bit, and if i have any questions i'll pop back in here :)

All other points are noted. This is the second time i get dissed for using $var != NULL. so i'll have to do something about that :)

One last thing, can you plz elaborate more on the security concern of using $_SERVER['PHP_SELF']... jsut for general knowledge.

Again, thanx for the great feedback!!

--
Al-Faisal El-Dajani
Tel: +962-7-77 799 781
P.O Box: 140056
11814 Amman, Jordan
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups "Jordan PHP Users Group" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at http://groups.google.com/group/JoPHP
http://Jolug.org/
-~----------~----~----~----~------~----~------~--~---

Reply via email to