


Notes on developing micro-malls with PHP
Compared with Java, C, C#, Python and other languages, PHP has more advantages in the mall. The biggest advantages are high development efficiency, many framework choices, and many open source products to choose from, which can greatly reduce development costs and speed up product iteration, such as the open source malls DSMall, DSHOP, DSKMS, etc. developed based on the Thinkphp framework. Based on this Product development can greatly speed up development and bring projects online quickly, while the Thinkphp framework can be directly upgraded.
Under normal circumstances, we need to pay attention to PHP security knowledge during our own development process. Here are some common security issues.
1.SQL injection
SQL injection is one of the biggest threats to common websites. If the database is attacked by SQL injection, all of your databases can be obtained. There are two current mainstream solutions. Escape user-entered data or use encapsulated statements. Generally, an encapsulated function is used to filter the data submitted by the user.
2.XSS
XSS is also called CSS (Cross Site Script), a cross-site scripting attack. It refers to a malicious attacker inserting malicious html code into a Web page. When a user browses the page, the html code embedded in the Web will be executed, thereby achieving the special purpose of maliciously attacking the user.
The correct approach is to resolutely not trust any input from the user and filter out all special characters in the input. This will eliminate most XSS attacks.
3. The most commonly used defense method is to generate a CSRF token encrypted secure string, generally called a Token. Every time you construct a form on a web page, put the Token token in a hidden field in the form. The Token token in the Session is better than Yes, it will be passed only if the verification is successful.
If you carry out secondary development in the open source mall system in these TP frameworks, you should pay attention to the following points:
1. Set public The directory is the only externally accessible directory. Do not put resource files into the application directory;
2. Turn on form token verification to avoid repeated submission of data, which can play a role in CSRF defense; 3. Use the request variable acquisition method provided by the framework (Request class param method and input helper function) instead of native system variables to obtain user input data; 4. Set default_filter filtering rules for different application requirements (there is no filtering by default) Rules), common security filtering functions include stripslashes, htmlentities, htmlspecialchars and strip_tags, etc. Please choose the most appropriate filtering method according to the business scenario; 5. Use verification classes or verification methods to Set necessary validation rules for business data; Recommended tutorial:PHP video tutorial
The above is the detailed content of What should you pay attention to when developing micro-mall in PHP?. For more information, please follow other related articles on the PHP Chinese website!

php把负数转为正整数的方法:1、使用abs()函数将负数转为正数,使用intval()函数对正数取整,转为正整数,语法“intval(abs($number))”;2、利用“~”位运算符将负数取反加一,语法“~$number + 1”。

实现方法:1、使用“sleep(延迟秒数)”语句,可延迟执行函数若干秒;2、使用“time_nanosleep(延迟秒数,延迟纳秒数)”语句,可延迟执行函数若干秒和纳秒;3、使用“time_sleep_until(time()+7)”语句。

php除以100保留两位小数的方法:1、利用“/”运算符进行除法运算,语法“数值 / 100”;2、使用“number_format(除法结果, 2)”或“sprintf("%.2f",除法结果)”语句进行四舍五入的处理值,并保留两位小数。

判断方法:1、使用“strtotime("年-月-日")”语句将给定的年月日转换为时间戳格式;2、用“date("z",时间戳)+1”语句计算指定时间戳是一年的第几天。date()返回的天数是从0开始计算的,因此真实天数需要在此基础上加1。

php字符串有下标。在PHP中,下标不仅可以应用于数组和对象,还可应用于字符串,利用字符串的下标和中括号“[]”可以访问指定索引位置的字符,并对该字符进行读写,语法“字符串名[下标值]”;字符串的下标值(索引值)只能是整数类型,起始值为0。

方法:1、用“str_replace(" ","其他字符",$str)”语句,可将nbsp符替换为其他字符;2、用“preg_replace("/(\s|\ \;||\xc2\xa0)/","其他字符",$str)”语句。

php判断有没有小数点的方法:1、使用“strpos(数字字符串,'.')”语法,如果返回小数点在字符串中第一次出现的位置,则有小数点;2、使用“strrpos(数字字符串,'.')”语句,如果返回小数点在字符串中最后一次出现的位置,则有。

在php中,可以使用substr()函数来读取字符串后几个字符,只需要将该函数的第二个参数设置为负值,第三个参数省略即可;语法为“substr(字符串,-n)”,表示读取从字符串结尾处向前数第n个字符开始,直到字符串结尾的全部字符。


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

WebStorm Mac version
Useful JavaScript development tools

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

DVWA
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is very vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, to help web developers better understand the process of securing web applications, and to help teachers/students teach/learn in a classroom environment Web application security. The goal of DVWA is to practice some of the most common web vulnerabilities through a simple and straightforward interface, with varying degrees of difficulty. Please note that this software

Zend Studio 13.0.1
Powerful PHP integrated development environment
