- Joined
- Apr 6, 2008
- Messages
- 575
- Reaction score
- 193
Hello People,
So I’m stuck at a little cross-road at the moment, for some reason when I get into coding something I don’t stop and think about the security implications that my methods could cause. Hence why I’m asking for a second opinion on the matter.
So at the moment I’m using the following function to return data about a user to the script, however after thinking about it I’m certain it may cause problems down the road.
Is this a safe way of performing a search? Or is there another way I could perform the query better? All feedback would be appreciated.
So I’m stuck at a little cross-road at the moment, for some reason when I get into coding something I don’t stop and think about the security implications that my methods could cause. Hence why I’m asking for a second opinion on the matter.
So at the moment I’m using the following function to return data about a user to the script, however after thinking about it I’m certain it may cause problems down the road.
PHP:
function UserInfo ($type)
{
$username = $_SESSION['USERNAME'];
$var = $GLOBALS['DATA']->query("SELECT * FROM users WHERE username = '".$username."'");
while ($row = $var->fetch_assoc())
{
switch ($type)
{
case "example":
return $row['avatar'];
break;
case "example2":
return $row['avatar2'];
break;
}
}
}


