PHP技术咨询:PHP7.1会话传页面名是否合规及新手建站实践
Answers to Your PHP Development Questions
Hey there! Since you're diving into PHP to build a social site and already have some foundational code going (header.php and index.php), let's tackle your questions clearly and practically.
1. Is Passing Page Names via Session a Good Practice in PHP 7.1?
Short answer: Generally, no—it's not a recommended practice, and here's why:
- Session storage is meant for persisting user-specific state (like login status, shopping cart contents, or user preferences) across multiple requests, not for passing transient data like page names. Wasting session resources on non-essential data can bloat server memory, especially as your user base grows.
- Page names/identifiers are already easily accessible via server superglobals without needing session storage. For example:
- Get the current script name with
basename($_SERVER['PHP_SELF']) - Get the full request URI with
$_SERVER['REQUEST_URI'] - These are lightweight, direct, and don't clutter your session data.
- Get the current script name with
- If you're trying to track a user's browsing history, there are better alternatives: store the path in a cookie (for non-sensitive tracking) or log it to a database (if you need persistent, user-specific history). Session storage isn't ideal here because sessions can expire or be cleared by the user.
Note: PHP 7.1's session behavior doesn't change this core recommendation—it works the same way as newer PHP versions when it comes to appropriate session usage.
2. Key Good & Bad Practices for Your PHP Social Site (As a Beginner)
Since you already have modular files like header.php, you're off to a great start! Here's how to build on that with solid practices:
Recommended Good Practices
- Double down on modularization: Keep building reusable components—footer.php, a shared
functions.phpfor common logic (like database connections, user validation), and separate files for core features (e.g.,user_auth.phpfor login/signup,post_handler.phpfor creating posts). This keeps your code clean and easy to debug. - Validate & sanitize all user input: Social sites rely heavily on user-generated content, so never trust input directly. Use:
filter_input()to sanitize GET/POST data before using ithtmlspecialchars()when outputting user content to the browser to prevent XSS attacks- Prepared statements with PDO or mysqli to avoid SQL injection when interacting with your database
- Secure password handling: Always use
password_hash()when storing user passwords andpassword_verify()to check login credentials—PHP 7.1 fully supports these functions, and they're far more secure than manual hashing or storing plain text. - Proper error handling: In development, enable full error reporting with:
In production, turn off display errors and log them to a file instead—never show raw error messages to your users (they can expose sensitive code details).error_reporting(E_ALL); ini_set('display_errors', 1); - Limit session usage: Only store critical user state in sessions (like user ID, login status). Avoid storing temporary or easily retrievable data (like page names) as we discussed earlier.
Bad Practices to Avoid
- Mixing logic and presentation: Don't cram database queries or complex business logic directly into your header.php or index.php. Keep view files (like index.php) focused on displaying content, and move logic to separate PHP files.
- Hardcoding sensitive data: Never write database credentials, API keys, or secret tokens directly into your main code files. Store them in a separate config file (e.g.,
config.php) and place it outside your web root directory to prevent public access. - Ignoring CSRF protection: For any form that modifies data (like posting a status, updating a profile), add a CSRF token. Generate a unique token in the session, include it as a hidden field in your form, and verify it when the form is submitted. This prevents cross-site request forgery attacks.
- Overusing
$_SESSIONor global variables: Avoid dumping data into sessions or global variables "just in case"—it leads to messy, hard-to-maintain code. Only use sessions for what's necessary.
内容的提问来源于stack exchange,提问作者LuckyLuke
相关产品推荐
相关产品推荐

