March 4, 200818 yr Hi Guys, Just wondering, those of you who use a PHP navigation to include your pages, what do you think the best way to do it is? Personally, I use my own modified code of: <?php if (isset($_GET['c'])) { if (file_exists("".$_GET['c'].".php")) { include "".$_GET['c'].".php"; } else { include "error.php"; } } else { include "home.php"; } ?> I'm fed up of doing, for example: mypage.php?c=about Is there a better way of doing it?
March 4, 200818 yr well you could always use a htaccess mode_rewrite to change www.mysite.com/mysite.php?c=about to www.mysite.com/page/about or www.mysite.com/about.html (would only work if there are NO other public .html files) at any rate, using a get straight off is a bed idea, because if you have a file structure like this: <?php include "allMyReallySecretSettings.php"; include "andMySQLPassword.php"; mysql_connect( ... ); include $_GET['c'].".php"; ?>... Then all I would need to is save this file to my server: <?php print_r( get_defined_constants( true ) ); ?> and then go to : www.mysite.com/mysite.php?c=http://www.richardlyon.co.uk/stealXandersStuff and I have your mysql passwords, maybe even your system passwords ... if I was a malicious sort I might be inclined to wipe your database, or change the contents so that every field is "Hacked by Sly Stalone" You really need to use aliases for names, so you could use a switch, like so: switch $_GET['c'] { case "about" : $page = "about.php"; break; case "contact" : $page = "contact.php"; break; default : $page = "home.php"; break; }
March 7, 200818 yr Hello Sorry, this isn't really related, but why do you write includes like this: include "".$_GET['c'].".php"; 1. The double double quote at the start? 2. Double quotes around the .php? Double quotes on any strings for that matter? 3. No brackets? I'm not attacking, just curious why? I usually write them like: include($_GET['c'].'.php'); Also I agree with php_penguin, never trust user data. You're just asking for it otherwise
March 16, 200818 yr If you don't want to code in all the possible pages, as in php_penguin's example, just make sure you have some error checking and don't use the data straight from the user input; make sure you check that it's looking for a locally stored file, for example.
March 16, 200818 yr LilJames, the code is meant to be used a central access file (eg, index.php) which would also include any class references and entity parsers. The requested $page would then be included (require'd) after the switch flow, therefore it would not be included on every page, rather as just one page.
Create an account or sign in to comment