Return-Path: <squirrelmail-plugins-admin@lists.sourceforge.net>
Received: from muffin ([unix socket])
	by muffin (Cyrus v2.1.13) with LMTP; Thu, 26 Jun 2003 15:45:41 -0400
X-Sieve: CMU Sieve 2.2
Return-Path: <squirrelmail-plugins-admin@lists.sourceforge.net>
Received: from sc8-sf-list2.sourceforge.net (lists.sourceforge.net [66.35.250.206])
	(using TLSv1 with cipher EDH-RSA-DES-CBC3-SHA (168/168 bits))
	(No client certificate requested)
	by muffin.linuxnotes.net (Postfix) with ESMTP id 7943C2493C
	for <quincy@linuxnotes.net>; Thu, 26 Jun 2003 15:45:41 -0400 (EDT)
Received: from sc8-sf-list1-b.sourceforge.net ([10.3.1.13] helo=sc8-sf-list1.sourceforge.net)
	by sc8-sf-list2.sourceforge.net with esmtp (Exim 3.31-VA-mm2 #1 (Debian))
	id 19VcXp-0001oI-00; Thu, 26 Jun 2003 12:36:33 -0700
Received: from host39.hostcentric.com ([216.65.63.39] helo=patiencehosting.net)
	by sc8-sf-list1.sourceforge.net with esmtp (Exim 3.31-VA-mm2 #1 (Debian))
	id 19VcWk-0006tg-00
	for <squirrelmail-plugins@lists.sourceforge.net>; Thu, 26 Jun 2003 12:35:26 -0700
Received: from angrynerds.com (tycho [127.0.0.1])
	by patiencehosting.net (Postfix) with SMTP
	id CAA0F3315D; Thu, 26 Jun 2003 12:27:37 -0700 (PDT)
Received: from 155.14.18.141
        (SquirrelMail authenticated user paul@angrynerds.com)
        by openguild.net with HTTP;
        Thu, 26 Jun 2003 12:27:37 -0700 (PDT)
Message-ID: <4492.155.14.18.141.1056655657.squirrel@openguild.net>
Subject: Re: [SM-PLUGINS] Re: address group plugin
From: <pdontthink@angrynerds.com>
To: <quincy@linuxnotes.net>
In-Reply-To: <54604.192.204.186.114.1056653624.squirrel@linuxnotes.net>
References: <20030626021911.3948.qmail@web21303.mail.yahoo.com>
        <4712.68.80.54.61.1056622238.squirrel@linuxnotes.net>
        <000b01c33be4$61d61c30$1601a8c0@surfglobal.net>
        <54218.192.204.186.114.1056634932.squirrel@linuxnotes.net>
        <002401c33bf0$052a3d70$1601a8c0@surfglobal.net>
        <3541.65.246.246.82.1056639663.squirrel@www.wingfoot.org>
        <54604.192.204.186.114.1056653624.squirrel@linuxnotes.net>
X-Priority: 3
Importance: Normal
Cc: <rainbear+lists@wingfoot.org>, <paultest@surfglobal.net>,
	<squirrelmail-plugins@lists.sourceforge.net>
Reply-To: pdontthink@angrynerds.com
X-Mailer: SquirrelMail (version 1.2.11 [cvs])
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable
Sender: squirrelmail-plugins-admin@lists.sourceforge.net
Errors-To: squirrelmail-plugins-admin@lists.sourceforge.net
X-BeenThere: squirrelmail-plugins@lists.sourceforge.net
X-Mailman-Version: 2.0.9-sf.net
Precedence: bulk
List-Help: <mailto:squirrelmail-plugins-request@lists.sourceforge.net?subject=help>
List-Post: <mailto:squirrelmail-plugins@lists.sourceforge.net>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins>,
	<mailto:squirrelmail-plugins-request@lists.sourceforge.net?subject=subscribe>
List-Id: Squirrelmail Plugins Mailing List <squirrelmail-plugins.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins>,
	<mailto:squirrelmail-plugins-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum=squirrelmail-plugins>
X-Original-Date: Thu, 26 Jun 2003 12:27:37 -0700 (PDT)
Date: Thu, 26 Jun 2003 12:27:37 -0700 (PDT)

> Wooohooo!!
>
> Ok, I *am* still a newbie so it takes me a little while, but I believe =
I
> have your answer!
>
> Check /etc/php.ini and look for
>
> register_globals        =3D       Off
>
> Change to:
>
> register_globals        =3D       On
>
> and you should be golden.

Ouch.  I didn't realize this plugin wasn't compatible with rg=3Doff.  Tha=
t's
not so good.  This is a security issue, and thus many people will not be
able to set it to On.  I'm glad this came up, actually, because that is
one glaring ommission I made on the plugin documentation rewrite.  I will
be adding that to the Plugin Standards document...

Fixing it to work with rg=3Doff isn't very hard at all, and it's definite=
ly
something you should make as a priority for the plugin if you have the
time.  It usually boils down to putting a line like this (one for each
POST/GET variable) at the top of each file that is called from a <form>
submission:

  global $variable_name;
  sqgetGlobalVar('variable_name', $variable_name, SQ_FORM);

cheers,

  paul




-------------------------------------------------------
This SF.Net email is sponsored by: INetU
Attention Web Developers & Consultants: Become An INetU Hosting Partner.
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission!
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
--
squirrelmail-plugins mailing list
List Address: squirrelmail-plugins@lists.sourceforge.net
List Info: https://lists.sourceforge.net/lists/listinfo/squirrelmail-plugins
http://squirrelmail.org/cvs

