Req #47926 [Opn]: It would be nice if there were a temporary conditions control structure
| From: | cmb@php.net | Date: | Sat, 02 May 2015 13:02:08 +0000 |
| Subject: | Req #47926 [Opn]: It would be nice if there were a temporary conditions control structure | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192458@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=47926&edit=1
ID: 47926
Updated by: cmb@php.net
Reported by: jeremy dot tharp at gmail dot com
Summary: It would be nice if there were a temporary
conditions control structure
Status: Open
Type: Feature/Change Request
-Package: Feature/Change Request
+Package: *General Issues
Operating System: Redhat Linux
PHP Version: 5.2.9
Block user comment: N
Private report: N
New Comment:
A "bit" late, but anyway: as of PHP 5.3 you could make use of a
closure, and write conversion_space as a function
function conversion_space($func) {
convert_user();
$func();
convert_user_back();
}
which can be called like so:
conversion_space(function () {
// some code
});
Previous Comments:
------------------------------------------------------------------------
[2009-04-08 18:53:37] jeremy dot tharp at gmail dot com
Description:
------------
This isn't really a bug, but I think it would be great to have a control structure that has
temporary execution parameters. Consider it an execution space similar to a while or switch, etc.
The reason I could use it in this particular instance is for security reasons. For certain code, I
need to elevate a logged in user's "status" to temporarily give them super user
permissions. Basically I temporarily convert the user, run the code, then convert them back.
convert_user();
execute_code_here();
convert_user_back();
This works great, of course, but if I have to do this 300 times, there is a decent chance that I
would forget to convert_user_back();, causing a security hole (the user would then be logged in as a
super user).
It would be great if I could do something like
execspace conversion_space ($params[]) {
function start () {
convert_user();
}
function stop () {
convert_user_back();
}
}
Then in my actual code, I would do:
conversion_space { // start function executes here
// execute some code
} // stop function executes here
This way, it is grammatically impossible to implement the structure without closing it.
I think this would be a powerful control structure for the language. Perhaps there is an equally
useful solution that I am unaware of, but if not, I think implementing it is worth consideration
(and if there is, I would certainly appreciate the enlightenment!)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=47926&edit=1