-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Garvin Hicking schrieb:
Hi!
Actually that's not a solution to the problem. PMA needs to be fed SQL commands, and we need to accept the via POST.
yes, but we should escape it before displaying in browser
Ah, I overread that. Yes, escaping SQL when displaying it would be wise.
- We need to utilize sessions. Only via sessions, form tokens could be
easily implemented, because a server-token needs to be compared with a client-token.
sessions already utilized
Seems I missed that, too. Since when does PMA use sessions, and what are they
2.8
currently used for? Did I also miss session saving of large SQL queries when
no, this is not done at the moment
only request independent data is saved in session, data that does not change if someone uses multiple windows with phpMyAdmin, this is currently only configuration and themes
browsing rows to get rid of the "?" editing buttons and max-GET-length exceeded problems?
i do not know this problem!? wasn't this fixed with 'subforms'?
- -- Sebastian Mendel
www.sebastianmendel.de