SQLInjection 대응을 위해 파일 상단부에 $_POST, $_GET의 원하는 변수 타입명 지정

This commit is contained in:
2018-04-14 01:32:13 +09:00
parent 14578fa828
commit 37f56f05b6
51 changed files with 374 additions and 26 deletions
+92
View File
@@ -7,6 +7,98 @@ include "func_auction.php";
include "func_string.php";
include "func_history.php";
class Util{
private function __construct(){
}
private static function _parseReq($value, $type)
{
if (is_array($value)) {
if ($type === 'array_int') {
return array_map('intval', $value);
}
if ($type === 'array_string') {
return array_map(function ($item) {
return (string)$item;
}, $value);
}
if ($type === 'array') {
return $value;
}
throw new \InvalidArgumentException('지원할 수 없는 type 지정. array 가 붙은 type이어야 합니다');
}
if ($type === 'bool') {
$value = strtolower($value);
if ($value === 'false' || $value === 'no' || $value === 'n' || $value === 'x' || $value === 'null') {
return false;
}
return !!$value;
}
if ($type === 'int') {
return (int)$value;
}
if ($type === 'float') {
return (float)$value;
}
if ($type === 'string') {
return (string)$value;
}
throw new \InvalidArgumentException('올바르지 않은 type 지정');
}
/**
* $_POST, $_GET에서 값을 가져오는 함수. Util::array_get($_POST[$name]) 축약 가능.
* 타입이 복잡해질 경우 함수를 통하지 않고 json으로 요청할 것을 권장.
*
* @param string $name 가져오고자 하는 key 이름.
* @param string $type 가져오고자 하는 type. [string, int, float, bool, array, array_string, array_int]
* @param mixed $ifNotExists 만약 $_POST와 $_GET에 값이 없을 경우 반환하는 변수. 값은 $type을 검사하지 않음.
* @return int|float|string|array|null
* @throws \InvalidArgumentException
*/
public static function getReq($name, $type = 'string', $ifNotExists = null)
{
if (isset($_POST[$name])) {
$value = $_POST[$name];
} elseif (isset($_GET[$name])) {
$value = $_GET[$name];
} else {
return $ifNotExists;
}
return static::_parseReq($value, $type);
}
/**
* $_POST에서 값을 가져오는 함수. Util::array_get($_POST[$name]) 축약 가능. $_GET에서도 가져올 있다면 getReq 사용.
* 타입이 복잡해질 경우 함수를 통하지 않고 json으로 요청할 것을 권장.
*
* @param string $name 가져오고자 하는 key 이름.
* @param string $type 가져오고자 하는 type. [string, int, float, bool, array, array_string, array_int]
* @param mixed $ifNotExists 만약 $_GET과 $_POST에 값이 없을 경우 반환하는 변수. 값은 $type을 검사하지 않음.
* @return int|float|string|array|null
* @throws \InvalidArgumentException
*/
public static function getPost($name, $type = 'string', $ifNotExists = null)
{
if (isset($_POST[$name])) {
$value = $_POST[$name];
} else {
return $ifNotExists;
}
return static::_parseReq($value, $type);
}
}
/// 0.0~1.0 사이의 랜덤 float
function randF(){
return mt_rand() / mt_getrandmax();