Book Image

CodeIgniter 1.7 Professional Development

By : Adam Griffiths
Book Image

CodeIgniter 1.7 Professional Development

By: Adam Griffiths

Overview of this book

<p>CodeIgniter is an open source PHP framework with a small footprint and exceptional performance. It gives you a rich set of libraries for common tasks, with a simple interface to access them. There are several unexplored aspects of CodeIgniter that can help developers build applications more easily and quickly. In this book, you will learn the intricacies of the framework and explore some of its hidden gems.<br /><br />If you want to get the most out of CodeIgniter, this book is for you. It teaches you what you need to know to use CodeIgniter on a daily basis. You will create mini-applications that teach a specific technique and let you build on top of the base. <br /><br />This book will take you through developing applications with CodeIgniter. You will learn how to make your CodeIgniter application more secure than a default installation, how to build large-scale applications and web services, how to release code to the community, and much more. You will be able to authenticate users, validate forms, and also build libraries to complete different tasks and functions.<br /><br />The book starts off introducing the framework and how to install it on your web server or a local machine. You are introduced to the Model-View-Controller design pattern and how it will affect your development. Some important parts of the CodeIgniter Style Guide are included to keep CodeIgniter development as standardized as possible; this helps greatly when working as part of a team or taking on an old CodeIgniter project. You will quickly move on to how CodeIgniter URLs work and learn about CodeIgniter-specific files such as helpers and plugins. By the time you finish this book, you will be able to create a CodeIgniter application of any size with confidence, ease, and speed.</p>
Table of Contents (16 chapters)
CodeIgniter 1.7 Professional Development
Credits
About the Author
About the Reviewers
Preface
Index

Database security


Another very important part of general application security is that of your database. Ensuring that your queries are all correct, that all data has been escaped before you use it in a query, and never ever trusting any user input will all help with safeguarding your database.

Escape queries

We have already been over the methods that CodeIgniter uses to escape your data, at the start of this chapter. This time around we'll go over how to escape the different parts of a query without CodeIgniter, as this is a skill that every developer should have.

Firstly, all database table names and field names should be escaped by using backticks (`). This will also avoid any issues where the name is a reserved word. This is especially useful when using a WHERE clause that uses the primary key id field. Here's an example:

SELECT * FROM `users` WHERE `username` = '$username' AND `id` = '$id'

Secondly, all variables that are included in a query should be properly escaped by using one of the...