[PHP] Question about having multiple files.

it might indeed be easyer but oh well any program will be able to acess the memory location where that variable is located, and i really mean any program..not just php scripts. of course you maybe not be expecting to get hacked.

every variable should be either temporal or protected.
 
it might indeed be easyer but oh well any program will be able to acess the memory location where that variable is located, and i really mean any program..not just php scripts. of course you maybe not be expecting to get hacked.

every variable should be either temporal or protected.


I have planned for and made preperations incase some one trys to hack it already, but i know i havnt covered it all.

I get what you are saying, however this still brings up the question "How would you do it?" if not with globals, then with what other than me making a lot of extra code and / or redoing the whole site in OOP, as it stands i might as well start over again if im going to do that :p

P.S. Incase anyone is wondering i am making a CMS.
 
ok let me explain a thing, i'm no wiz in php but if static works like in c this should suffice

static $pointer = &$var

or something like that....this will make that $pointer has the memory adress of where $var is stored and static will make that after a function the var $pointer will still exist.

over different files prolly won't work cause php is a scripting language, unless you include all the files you need to work with in the file that has the declaration of the var and after the declaration.

and theres another method that i'm not sure of how it works that you can call php script with arguments.

Anyways try to realize why PHP made Super-Globals.
 
Last edited:
ok let me explain a thing, i'm no wiz in php but if static works like in c this should suffice

static $pointer = &$var

or something like that....this will make that $pointer has the memory adress of where $var is stored and static will make that after a function the var $pointer will still exist.

over different files prolly won't work cause php is a scripting language, unless you include all the files you need to work with in the file that has the declaration of the var and after the declaration.

and theres another method that i'm not sure of how it works that you can call php script with arguments.

Anyways try to realize why PHP made Super-Globals.

I cant include all the files used in this case, because all of the files have functions when they are included in more than one file i will start getting function already declared in blah blah blah errors.

According to what you said the *only* other way i am getting out of this is i would have to do OOP, which would require me to recode almost the entire thing.

Do you have a link to this other method?
 
ermmmm...why would you declare same function 2 times oO?

anyways m8 i was just poiting out that it's unsafe to work with globals

wots CMS btw?

CMS - Content management system ( afaik. What im coding is more along the lines of a mini version of php-nuke / joomla / e107 / etc just made for my needs ).

Also, im not declaring them twice :p However, if i have functions in the files, and include those files in other files, the functions will carry over to those files, so when they are included it will think i have the same functions declared more than one time.

Also, i understand :p , im just saying i dont know of another way to do it that dosnt involve recoding the whole thing.
 
Last edited:
function_exists()
Description
bool function_exists ( string function_name )

Checks the list of defined functions, both built-in (internal) and user-defined, for function_name. Returns TRUE on success or FALSE on failure.

EDIT:
well found you an easy way for you, way more secure the way Super globals are handeled

$GLOBALS array

Def.:
The $GLOBALS array is an associative array with the name of the global variable being the key and the contents of that variable being the value of the array element. Notice how $GLOBALS exists in any scope, this is because $GLOBALS is a superglobal.

EDIT2: and you do have require() and require_once() wich is easyer to use then function_exists()

sorry for not helping earlyer was being a bit lazy. all this concepts can be found in php.net
 
Last edited:
function_exists()
Description
bool function_exists ( string function_name )

Checks the list of defined functions, both built-in (internal) and user-defined, for function_name. Returns TRUE on success or FALSE on failure.

EDIT:
well found you an easy way for you, way more secure the way Super globals are handeled

$GLOBALS array

Def.:
The $GLOBALS array is an associative array with the name of the global variable being the key and the contents of that variable being the value of the array element. Notice how $GLOBALS exists in any scope, this is because $GLOBALS is a superglobal.

EDIT2: and you do have require() and require_once() wich is easyer to use then function_exists()

sorry for not helping earlyer was being a bit lazy. all this concepts can be found in php.net

Np, i will check it out aswell :)
 
GriffinHeart, seriously, what are you blattering about? Unsafe? To read memory adresses on a server you already need direct access to it, if thats the case you can just as easy see the source! Also, with PHP you CANNOT access memory allocated by a different instance, so you don't even have to be worried about other websites on the same server reading your globals.

And even if this were the case, locally defined variabels suffer from exactly the same problems! Yes, they life shorter, but what difference does that make? Most PHP scripts never life longer then a few microseconds anyway!

There is NOTHING unsave about using globals, it only clutters up your global scope, but thats merely something to be carefull about, not a reason to avoid them alltogether! Why else would they even exist? They're there for people to use them, and true, there -are- more beautifull ways of passing on variables, but for a beginning programmer they're still there to be used!
 
sorry m8 but i have to disagree with you...and to asume that a webserver or any computer is free of malware is just being naive.
i'm not refering to php scripts acessing memory allocated by a different instances (altho it is a possible as in any language, in php you'd have to be dumb not to realise that a script not made by you was running). m8 go check out why php adopted Super Globals...that is all i can say without getting to much technical.

tbh ya it's being a bit paranoic to consider this kind of cenario...but if i'm a costumer i would rather use a service that is paranoic about this kind of stuff.

in the end i'm just poiting out that using globals is:
a) ugly
b) unsafe (generally unsafe in any language not just php)

Note: a program that sniffs memory acess can do it in microseconds aswell
 
Last edited:
There is NO reason to say globals are more unsave then locally defined variables, hell, in most languages with variable scope fallback there is no reall distinction whatsoever. Any sniffer program would just as easy snif locally defined variables, true they tend to live shorter but to a good sniffer that makes no destinction whatsoever.

PHP CANNOT read memory blocks created by other instances. Its the way its build. If that were the case, all I needed to do to hack -any- website is get an account with the same hosting provider, you'd think people'd notice something like that happening ;)

Not using globals because they are unsafe is like not walking down a street because martians could come crashing down from the sky and offer you icecream - although theoretically possible, it doesn't have any reall-life meaning whatsoever.

Lastly, even if a program could sniff variables, what difference would it make? If you're coding correctly you NEVER use plain-text passwords on your scripts, and the only reason to put information in globals is because its -very- general information, like errors or output settings, information thats freely available anyway.

Yes, there is something to be said about security, but you're just being silly here. If you want someone to make save websites, teach them about SQL injections, XSS exploits, PHP.ini settings, etc. Don't make them waste time on stuff like this.

And yes, I know for a fact that my webserver is free from mallware. Its a clean windows 2003 install, with all servicepacks and updates, behind a NAT that only allows trusted traffic trough certain appointed ports, and with only trusted applications installed on it. There is no way in hell its infected by mallware.
 
Last edited:
Back