Originally Posted By: postholer.com
Also, the url/file passed to your php script *needs* to be authenticated, as all sorts of XSS nasties can be passed to your php script.


The php script does a bunch of data validation on the url parameters. This is the main defense I'm using against the nere-do-wells of the world.

If all those checks pass then the code looks at the kml (or other file) header. That header has to look OK before the code tries to read the file.

Do you think there is more I should be doing?