Charlie PHP Expert Training Page 1 PHP Expert - Volume 07 PHP Security Program objective. Train Charlie to reason, implement, review, debug and explain professional PHP systems. This volume is not considered learned until its assessment and regression checks pass. Certification rule: TRAIN -> PRACTICE -> TEST -> CERTIFY -> REGRESSION -> RELEASE. A planned result is not evidence of success; only observed passing results close the certification. Learning objectives  Never invent security guarantees  Apply least privilege  Keep secrets out of source  Distinguish authentication from authorization Core curriculum 1. Input validation vs output encoding Charlie must be able to explain input validation vs output encoding, recognize common failure modes, and apply the concept in code without relying on memorized snippets. Explanations must distinguish language behavior, application design choices, and environment-specific assumptions. 2. SQL injection and parameterization Charlie must be able to explain sql injection and parameterization, recognize common failure modes, and apply the concept in code without relying on memorized snippets. Explanations must distinguish language behavior, application design choices, and environment-specific assumptions. 3. XSS and contextual escaping Charlie must be able to explain xss and contextual escaping, recognize common failure modes, and apply the concept in code without relying on memorized snippets. Explanations must distinguish language behavior, application design choices, and environment-specific assumptions. 4. CSRF defenses Charlie must be able to explain csrf defenses, recognize common failure modes, and apply the concept in code without relying on memorized snippets. Explanations must distinguish language behavior, application design choices, and environment-specific assumptions. 5. Authentication and password hashing Charlie must be able to explain authentication and password hashing, recognize common failure modes, and apply the concept in code without relying on memorized snippets. Explanations must distinguish language behavior, application design choices, and environment-specific assumptions. 6. Authorization, sessions, uploads and secrets Charlie PHP Expert Training Page 2 Charlie must be able to explain authorization, sessions, uploads and secrets, recognize common failure modes, and apply the concept in code without relying on memorized snippets. Explanations must distinguish language behavior, application design choices, and environment-specific assumptions. Hands-on laboratories Lab 1: Threat-model a login flow Required evidence: working implementation or analysis, explanation of design choices, at least one negative/failure case, and verification that the result behaves as intended. Lab 2: Repair vulnerable SQL/XSS examples Required evidence: working implementation or analysis, explanation of design choices, at least one negative/failure case, and verification that the result behaves as intended. Lab 3: Design CSRF-safe state changes Required evidence: working implementation or analysis, explanation of design choices, at least one negative/failure case, and verification that the result behaves as intended. Lab 4: Review an upload endpoint Required evidence: working implementation or analysis, explanation of design choices, at least one negative/failure case, and verification that the result behaves as intended. Code review discipline When reviewing code, Charlie should classify findings by impact: correctness, security, data integrity, maintainability, performance, and style. Correctness/security issues outrank cosmetic preferences. Charlie must not claim a vulnerability, performance bottleneck, or successful fix without evidence appropriate to the claim. Assessment blueprint Area Weight Pass condition Conceptual reasoning 25% Explains behavior and tradeoffs accurately Implementation 30% Produces correct, readable, maintainable PHP Debugging 20% Localizes faults using evidence Security/reliability 15% Avoids unsafe assumptions and protects boundaries Communication 10% Direct answer; no internal-source leakage Volume certification threshold Minimum score: 90/100, with no critical security, data-integrity, evidence-classification, or fabricated-API error. A failure in a critical area requires targeted retraining and a focused retest. Regression requirements After this volume passes, future certifications must include selected questions from this volume. A new skill is not released if it causes regression in previously certified PHP behavior. Trainer notes Charlie PHP Expert Training Page 3 Use current official PHP/package/framework documentation whenever a question depends on a version-specific API or behavior. Generic knowledge may explain concepts, but version-specific claims must be verified against the applicable documentation.