blob: 3deb431c7f5cd569f86dafec407515758e727b41 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
|
<!--
$FML: restriction.sgml,v 1.4 2001/10/21 02:18:09 fukachan Exp $
-->
<chapter id="restriction">
<title>
����
</title>
<sect1 id="restriction.class">
<title>
FML::Restriction ���饹
</title>
<para>
���ϥǡ����䡢
���ޥ�ɤ� ACL ��
FML::Restriction ���饹�ʲ��˥⥸�塼������֤��뤳�Ȥˤ��Ƥ��ޤ���
</para>
<para>
�㤨�С�CGI �Ǥ�
FML::Restriction::CGI ���饹�Υ⥸�塼����Ѥ���
���ϥǡ�������������ɽ������˼��ޤ뤫�ɤ������θ����Ƥ��ޤ���
</para>
<para>
FML::Restriction �ʲ��Ǥ�
Base ��Ѿ������ꤷ�ޤ�����
¾�Υ⥸�塼��Ǥϡ�FML::Restriction ���饹�� object composition
�Ȥ��ƻȤäƲ�������
�㤨�С�
<screen>
use FML::Restriction::CGI;
$safe = new FML::Restriction::CGI;
my $allowed_regexp = $safe->param_regexp();
if ($value =~ /^$allowed_regexp{$key}$) { ... ok, do something ... ;}
</screen>
�Τ褦�˻Ȥ��ޤ���
</para>
</sect1>
<sect1 id="restriction.cgi.input.data">
<title>
CGI �ˤ��������ϥǡ���������
</title>
<para>
CGI �Ǥ�
FML::Restriction::CGI ���饹�Υ⥸�塼����Ѥ���
���ϥǡ�������������ɽ������˼��ޤ뤫�ɤ������θ����ޤ���
</para>
<para>
�����ͤϡ����ҤΥ��饹���������¤���٤��Ǥ���
���Τ��ᡢľ�� param() ��ȤäƤϤ����ޤ���
ɬ�� safe_param_xxx() ��åɤ��̤��ƤΤߡ�
param() ( CGI �⥸�塼�� )����Υǡ������ϤƲ�������
</para>
<para>
�ʤ������Ϥ��줿������ɰ�����Ĵ�٤뤿��ˡ�
<screen>
for my $dirty_buf (param()) {
... check ...
}
</screen>
�Τ褦�ʹ�ʸ�ϵ���ɬ�פϤ���Ǥ��礦����
<screen>
param($dirtty_buf)
</screen>
�ʤɤȤϤ��ƤϤ����ޤ���ɬ��
<screen>
for my $key (param()) {
... check ...
if (key eq $key) {
value = safe_param_key()
}
}
</screen>
�Τ褦�˽Ʋ�������
</para>
</sect1>
</chapter>
|