Bug #62045 [Nab]: public access to a protected method
Edit report at https://bugs.php.net/bug.php?id=62045&edit=1
ID: 62045
Updated by: cataphract@php.net
Reported by: gonzalo123 at gmail dot com
Summary: public access to a protected method
Status: Not a bug
Type: Bug
Package: Class/Object related
Operating System: Linux
PHP Version: 5.3.13
Block user comment: N
Private report: N
New Comment:
Right. But it doesn't change anything. The type is only important to decide what the foo()
method is, and foo() is AnotherClass and OneClass.
Previous Comments:
------------------------------------------------------------------------
[2012-05-16 13:15:57] gonzalo123 at gmail dot com
$this->object is not an instance of OneClass.
$this->object is an instance of AnotherClass (look at the constructor).
------------------------------------------------------------------------
[2012-05-16 11:36:49] cataphract@php.net
$this->object is an instance of OneClass. $this->object->foo() is called. foo() is
protected and was defined in the context of OneClass. The access is done in the context of
AnotherClass. AnotherClass is a subclass of OneClass (the context where foo() was defined).
Therefore access is granted. I don't know what's your problem here.
------------------------------------------------------------------------
[2012-05-16 09:00:32] gonzalo123 at gmail dot com
But we are not accesing OneClass::foo. This access is allowed beacause of the
extends,we should not have access to use $this->object->foo();
$this is an instance of OneClass (it extends AnotherClass) but $this->object (we
load it with DI) is an instance of AnotherClass. foo is protected here and we are
accesing as a public method.
------------------------------------------------------------------------
[2012-05-16 08:51:07] cataphract@php.net
Access is granted on a class, not instance basis. This is by design.
------------------------------------------------------------------------
[2012-05-16 08:23:45] gonzalo123 at gmail dot com
Description:
------------
This code works, but it shouldn't, because AnotherClass::foo is protected.
It works only if "OneClass" extends "AnotherClass". If we dont't extends
"OneClass" with "AnotherClass" (in this example we don't need it) we will
see the
normal error:
Fatal error: Call to protected method AnotherClass::foo() from context 'OneClass'
Test script:
---------------
class AnotherClass {
protected function foo() {
return "bar";
}
}
class OneClass extends AnotherClass {
private $object;
public function __construct(AnotherClass $object) {
$this->object = $object;
}
public function myFunction() {
return $this->object->foo();
}
}
$obj = new OneClass(new AnotherClass());
echo $obj->myFunction();
Expected result:
----------------
Fatal error: Call to protected method AnotherClass::foo() from context 'OneClass'
Actual result:
--------------
"bar" (without Fatal error)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62045&edit=1
Thread (10 messages)