Req #44031 [Opn]: vprint treats private object elements as array elements

From: Date: Sun, 17 May 2015 18:28:15 +0000
Subject: Req #44031 [Opn]: vprint treats private object elements as array elements
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192715@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=44031&edit=1

 ID:                 44031
 Updated by:         cmb@php.net
 Reported by:        m dot beyer5 at gmx dot de
 Summary:            vprint treats private object elements as array
                     elements
 Status:             Open
 Type:               Feature/Change Request
-Package:            Feature/Change Request
+Package:            *General Issues
 Operating System:   Debian Linux
 PHP Version:        5.2.5
 Block user comment: N
 Private report:     N

 New Comment:

The behavior is not particularly related to vprinf(), but that is
rather how casting objects to arrays work in PHP, see
<http://3v4l.org/3R6QT>.


Previous Comments:
------------------------------------------------------------------------
[2008-02-03 12:50:12] m dot beyer5 at gmx dot de

Description:
------------
If an object is supplied instead of an array, v(s)printf takes the internal object elements as
elements despite of its visibility.
This is not only quite annoying but could be a security issue as well.

Reproduce code:
---------------
class foo
{
    private $x = 1;
    private $y = 2;
    
}

$array = new foo;
vprintf('%s < %s',$array);

Expected result:
----------------
An E_WARNING should be triggered.
Alternatively, vprintf could take an object instantiating or extending ArrayObject and behave
according to the objects functions.

Actual result:
--------------
vprintf prints:

1 < 2


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=44031&edit=1


Thread (5 messages)

« previous php.bugs (#192715) next »