Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Modern & Secure PHP Applications
Search
Ben Edmunds
August 12, 2014
Technology
2
110
Modern & Secure PHP Applications
What's new in PHP along with a focus on building secure apps. Presented on CodeMentor 08/12/2014.
Ben Edmunds
August 12, 2014
Tweet
Share
More Decks by Ben Edmunds
See All by Ben Edmunds
Longhorn PHP 2021 - Passing the Technical Interview Workshop
benedmunds
0
120
DevOpsDays Boston 2020 - Passing the Technical Interview
benedmunds
0
67
Midwest PHP 2020 - Web Scale System Design and Architecture
benedmunds
1
140
Modern and Secure PHP (SoutheastPHP 2018)
benedmunds
0
100
Level Up Your Career - PHP South Africa Keynote
benedmunds
0
880
Modern PHP, Standards, and Community (phpDay 2017)
benedmunds
1
850
Lone Star PHP 2017 - More Than Just a Hammer
benedmunds
0
510
Lone Star PHP 2017 - Your API is Bad and You Should Feel Bad
benedmunds
0
230
Intro to Laravel 5
benedmunds
1
500
Other Decks in Technology
See All in Technology
2025年になってもまだMySQLが好き
yoku0825
8
4.8k
LLMを搭載したプロダクトの品質保証の模索と学び
qa
0
1.1k
新アイテムをどう使っていくか?みんなであーだこーだ言ってみよう / 20250911-rpi-jam-tokyo
akkiesoft
0
300
サラリーマンの小遣いで作るtoCサービス - Cloudflare Workersでスケールする開発戦略
shinaps
2
460
💡Ruby 川辺で灯すPicoRubyからの光
bash0c7
0
120
20250910_障害注入から効率的復旧へ_カオスエンジニアリング_生成AIで考えるAWS障害対応.pdf
sh_fk2
3
260
RSCの時代にReactとフレームワークの境界を探る
uhyo
10
3.5k
フルカイテン株式会社 エンジニア向け採用資料
fullkaiten
0
8.8k
大「個人開発サービス」時代に僕たちはどう生きるか
sotarok
20
10k
「全員プロダクトマネージャー」を実現する、Cursorによる仕様検討の自動運転
applism118
22
11k
株式会社ログラス - 会社説明資料【エンジニア】/ Loglass Engineer
loglass2019
4
64k
20250913_JAWS_sysad_kobe
takuyay0ne
2
230
Featured
See All Featured
XXLCSS - How to scale CSS and keep your sanity
sugarenia
248
1.3M
Reflections from 52 weeks, 52 projects
jeffersonlam
352
21k
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
358
30k
Keith and Marios Guide to Fast Websites
keithpitt
411
22k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
53
2.9k
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
34
6k
Statistics for Hackers
jakevdp
799
220k
GraphQLとの向き合い方2022年版
quramy
49
14k
The World Runs on Bad Software
bkeepers
PRO
70
11k
No one is an island. Learnings from fostering a developers community.
thoeni
21
3.4k
Speed Design
sergeychernyshev
32
1.1k
Testing 201, or: Great Expectations
jmmastey
45
7.7k
Transcript
PHP modern & secure
Who is this guy? Ben Edmunds ! @benedmunds http://benedmunds.com
Who is this guy? Ben Edmunds ! Open Source Author
PHP Town Hall Podcast CTO at Mindfulware
Welcome to the Future
Welcome to the Future Exceptions Namespaces Closures
Welcome to the Future Statics PDO Short Arrays Security
Legit Tools
Legit Tools Built-in Server Unit Testing Composer
Welcome to! the Future
Great Scott!
Exceptions
None
Exceptions try { //your code goes here } catch (Exception
$e) { die($e->getMessage()); }
Exceptions try { //your code goes here } catch (Exception
$e) { die($e->getMessage()); }
Closures
None
Closures Route::get(‘/', function(){ return View::make(‘index'); ! });
Closures Route::get(‘/', function(){ return View::make(‘index'); ! });
Namespaces
None
Namespaces namespace Illuminate\Console; class Command { //…
Namespaces use Illuminate\Console\Command; namespace Illuminate\Console; class Command { //…
Namespaces use Illuminate\Console\Command; namespace Illuminate\Console; class Command { //…
Statics
None
Statics Class Route { public static function get() { //…
}
Statics Route::get(); Class Route { public static function get() {
//… }
Statics Route::get(); Class Route { public static function get() {
//… }
Statics NO $this $var = self::varAtDefinition; ! $var = static::varAtExec;
Short Array! Syntax
None
Short Array Syntax $array = array( 0 => ‘value1’, 1
=> ‘value2’, );
Short Array Syntax $array = [ 0 => ‘value1’, 1
=> ‘value2’, ];
Short Array Syntax $array = [ 0 => ‘value1’, 1
=> ‘value2’, ];
PDO
None
PDO Cross System
PDO Cross System MS SQL MySQL Oracle PostgreSQL SQLite CUBRID
Firebird Informix ODBC & DB2 4D
PDO Cross System Safe Binding
PDO $stmt = $db->prepare(‘ SELECT * FROM users WHERE id=:id
’); ! $stmt->bindParam(‘:id’, $id); $stmt->execute();
Security
Security SQL Injection HTTPS Password Hashing
Security Authentication Safe Defaults XSS & CSRF
None
Security //escaping input $stmt->bindParam(‘:id’, $id);
Security //escaping input $stmt->bindParam(‘:id’, $id); //escaping output htmlentities($_POST[‘name’]);
Security HTTPS / SSL ! Encrypts traffic across the wire
! Trusted sender and receiver ! Required by OAUTH 2
Security //authentication - access control if (!$user->inGroup(‘admin’)) { return ‘ERROR
YO’; }
Security //authentication - brute force if ($user->loginAttempts > 5) {
return ‘CAUGHT YA’; }
Security //safe password hashing password_hash($_POST['pass']);
Security //safe password hashing password_hash($_POST['pass']); //password verification password_verify($_POST['pass'], $u->pass);
Security //safe defaults class Your Controller { protected $var1 =
‘default value’; ! function __construct() { … } }
Security //safe defaults $something = false; ! foreach ($array as
$k => $v) { $something = $v->foo; if ($something == ‘bar’) { … } }
Security //Non-Persistent XSS ! http://www.yourSite.com/ ?page_num=2&per_page=50 ! Send the link
to someone, boom
Security //Persistent XSS ! Same idea, except with data that
is saved to the server and re-displayed
Security //XSS Protection ! <h1>Title</h1> Hello <?=htmlentities($name)?> ! !
Security //Cross Site Request Forgery //(CSRF) ! http://yourSite.com/ users/12/delete !
!
Security //CSRF Protection ! POST / PUT / UPDATE /
DELETE behind forms with one-time use tokens ! !
Security //CSRF Protection ! function generateCsrf() { $token = mcrypt_create_iv(
16, MCRYPT_DEV_URANDOM); Session::flash('csrfToken', $token); return $token; }
Security //CSRF Protection ! if ( $_POST['token'] == Session::get(‘csrfToken') )
{ … } !
Legit Tools
None
Built-in ! Web Server
Built-in Server $ php -S localhost:8000 ! PHP 5.4.0 Development
Server started… Listening on localhost:8000 Document root is /home/ben/htdocs Press Ctrl-C to quit
Composer
Another Package Manager!?
Composer Sane Package Management
Composer Autoloading
Composer PEAR, ha! packagist.org
Composer / composer.json ! { "require": { "stripe/stripe-php": "dev-master", "twilio/sdk":
"dev-master" } }
Composer $ php composer.phar update $ php composer.phar install
Composer $client = new Services_Twilio($sid, $tkn); ! $client->account ->messages ->sendMessage(…)
Unit Testing
None
Unit Testing PHPUnit Behat Mink Selenium CodeCeption PHPSpec
Unit Testing class ApiAuthTest extends PHPUnit_Framework_TestCase { ! public function
testVerify() { ! $auth = new apiAuth(); $this->assertTrue($auth->verify());
Unit Testing class ApiAuthTest extends PHPUnit_Framework_TestCase { ! public function
testVerify() { ! $auth = new apiAuth(); $this->assertTrue($auth->verify());
Unit Testing $ phpunit tests ! PHPUnit 3.3.17 by Sebastian
Bergmann. Time: 0.01 seconds OK (1 tests, 1 assertions)
Resources
None
Resources PHP.net
Resources Modern Frameworks Laravel Symfony2 Fuel PHP SlimPHP 2 Aura
for PHP Silex
Resources leanpub.com/ phptherightway PHPtheRightWay.com
Resources BuildSecurePHPapps.com Coupon Code: codementor $3 off http://buildsecurephpapps.com/?coupon=codementor
Q/A TIME! Ben Edmunds @benedmunds http://benedmunds.com http://buildsecurephpapps.com/?coupon=codementor