SQLInjection 대응을 위해 파일 상단부에 $_POST, $_GET의 원하는 변수 타입명 지정
This commit is contained in:
@@ -7,6 +7,98 @@ include "func_auction.php";
|
||||
include "func_string.php";
|
||||
include "func_history.php";
|
||||
|
||||
|
||||
class Util{
|
||||
private function __construct(){
|
||||
|
||||
}
|
||||
|
||||
private static function _parseReq($value, $type)
|
||||
{
|
||||
if (is_array($value)) {
|
||||
if ($type === 'array_int') {
|
||||
return array_map('intval', $value);
|
||||
}
|
||||
|
||||
if ($type === 'array_string') {
|
||||
return array_map(function ($item) {
|
||||
return (string)$item;
|
||||
}, $value);
|
||||
}
|
||||
|
||||
if ($type === 'array') {
|
||||
return $value;
|
||||
}
|
||||
|
||||
throw new \InvalidArgumentException('지원할 수 없는 type 지정. array 가 붙은 type이어야 합니다');
|
||||
}
|
||||
|
||||
if ($type === 'bool') {
|
||||
$value = strtolower($value);
|
||||
if ($value === 'false' || $value === 'no' || $value === 'n' || $value === 'x' || $value === 'null') {
|
||||
return false;
|
||||
}
|
||||
return !!$value;
|
||||
}
|
||||
if ($type === 'int') {
|
||||
return (int)$value;
|
||||
}
|
||||
if ($type === 'float') {
|
||||
return (float)$value;
|
||||
}
|
||||
if ($type === 'string') {
|
||||
return (string)$value;
|
||||
}
|
||||
|
||||
throw new \InvalidArgumentException('올바르지 않은 type 지정');
|
||||
}
|
||||
|
||||
/**
|
||||
* $_POST, $_GET에서 값을 가져오는 함수. Util::array_get($_POST[$name])을 축약 가능.
|
||||
* 타입이 복잡해질 경우 이 함수를 통하지 않고 json으로 요청할 것을 권장.
|
||||
*
|
||||
* @param string $name 가져오고자 하는 key 이름.
|
||||
* @param string $type 가져오고자 하는 type. [string, int, float, bool, array, array_string, array_int]
|
||||
* @param mixed $ifNotExists 만약 $_POST와 $_GET에 값이 없을 경우 반환하는 변수. 이 값은 $type을 검사하지 않음.
|
||||
* @return int|float|string|array|null
|
||||
* @throws \InvalidArgumentException
|
||||
*/
|
||||
public static function getReq($name, $type = 'string', $ifNotExists = null)
|
||||
{
|
||||
if (isset($_POST[$name])) {
|
||||
$value = $_POST[$name];
|
||||
} elseif (isset($_GET[$name])) {
|
||||
$value = $_GET[$name];
|
||||
} else {
|
||||
return $ifNotExists;
|
||||
}
|
||||
|
||||
return static::_parseReq($value, $type);
|
||||
}
|
||||
|
||||
/**
|
||||
* $_POST에서 값을 가져오는 함수. Util::array_get($_POST[$name])을 축약 가능. $_GET에서도 가져올 수 있다면 getReq 사용.
|
||||
* 타입이 복잡해질 경우 이 함수를 통하지 않고 json으로 요청할 것을 권장.
|
||||
*
|
||||
* @param string $name 가져오고자 하는 key 이름.
|
||||
* @param string $type 가져오고자 하는 type. [string, int, float, bool, array, array_string, array_int]
|
||||
* @param mixed $ifNotExists 만약 $_GET과 $_POST에 값이 없을 경우 반환하는 변수. 이 값은 $type을 검사하지 않음.
|
||||
* @return int|float|string|array|null
|
||||
* @throws \InvalidArgumentException
|
||||
*/
|
||||
public static function getPost($name, $type = 'string', $ifNotExists = null)
|
||||
{
|
||||
if (isset($_POST[$name])) {
|
||||
$value = $_POST[$name];
|
||||
} else {
|
||||
return $ifNotExists;
|
||||
}
|
||||
|
||||
return static::_parseReq($value, $type);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/// 0.0~1.0 사이의 랜덤 float
|
||||
function randF(){
|
||||
return mt_rand() / mt_getrandmax();
|
||||
|
||||
Reference in New Issue
Block a user