Skip to content

NonSecureParseStrUsage ​

error on by default

Group: Security · PhpStorm name: NonSecureParseStrUsageInspection

Called with a single argument, parse_str() / mb_parse_str() create variables in the current scope from user-supplied query strings, which can overwrite existing variables. Always pass the result array as second argument.

Example ​

php
<?php
function readQuery($raw)
{
    parse_str($raw);
    \mb_parse_str ($raw);

    parse_str($raw, $fields);
    mb_parse_str($raw, $more);
    return [$fields, $more];
}

Reported:

  • line 4: Pass a result array as second argument instead of creating variables.
  • line 5: Pass a result array as second argument instead of creating variables.

Configure ​

In custos.json:

json
{
  "rules": {
    "NonSecureParseStrUsage": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore NonSecureParseStrUsage

/**
 * @noinspection NonSecureParseStrUsageInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.