Raw $_GET and $_POST variables should never be accessed and used directly because they pose a risk of SQL injection, or other potential forms of exploitation using carefully crafted URLs and GET/POST parameters. The request service provides a security layer to help sanitize and ensure that these variables are safe to use.
Regardless of whether or not this is deemed a security issue in this particular case, it goes against Drupal coding standards and best practices. When using PHPCS to lint code against Drupal standards, this error message is produced:
The $_POST super global must not be accessed directly; inject the request_stack service and use $stack->getCurrentRequest()->request->get('g-recaptcha-response') instead.
All modules should comply with the Drupal coding standards, especially when it comes to potential security issues, to minimize vulnerabilities in the platform.
| Comment | File | Size | Author |
|---|---|---|---|
| #2 | 3124353-2.patch | 963 bytes | swatichouhan012 |
Issue fork recaptcha-3124353
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
swatichouhan012 commentedKindly review patch.
Comment #3
roderik de langen commentedConfirmed that the above fix works
Comment #4
anybody@swatichouhan012 thank you very much, but could you please update the issue summary with details, why this should be done and where this is documented?
Tests look good. Also it would be better to have this as MR against 3.x and 4.x
Comment #5
teknocat commentedComment #7
anybodyAs of https://symfony.com/doc/current/introduction/http_fundamentals.html the solution is correct, we please need some community feedback, if this works, then we can merge it soon.
Comment #8
roderik de langen commentedTested the patch again!
Comment #10
anybodyThanks @Roderik de Langen merged! :)