Bug #70088 [Opn]: is_callable() doesn't check if a class/method syntax is valid
| From: | olivier dot laviale at gmail dot com | Date: | Thu, 16 Jul 2015 13:50:39 +0000 |
| Subject: | Bug #70088 [Opn]: is_callable() doesn't check if a class/method syntax is valid | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194492@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70088&edit=1
ID: 70088
User updated by: olivier dot laviale at gmail dot com
Reported by: olivier dot laviale at gmail dot com
Summary: is_callable() doesn't check if a class/method syntax
is valid
Status: Open
Type: Bug
Package: Scripting Engine problem
Operating System: MacOS, Linux
PHP Version: 5.6.11
Block user comment: N
Private report: N
New Comment:
Yes, you can invoke methods with invalid names if __call() is implemented, I don't think
it's right, but that's a fact. My point is that the following code should return
false:
var_dump(is_callable('+{^not&a*callable}', true, $callable_name));
Unless '+{^not&a*callable}' is a valid function name.
Also, I strongly believe that "syntax_only" is misleading. This is not syntax check, this
is type check: a string, or an array with two values.
Previous Comments:
------------------------------------------------------------------------
[2015-07-16 13:33:05] ab@php.net
Maybe it could be improved if we check whether an object has __call() defined. But if it has
__call() - there's no chance to know exactly what is callable, say this would work
$obj->{"+{^not&a*callable}"}();. But I'd rather tend to say it is not a bug.
Thanks.
------------------------------------------------------------------------
[2015-07-16 12:53:41] olivier dot laviale at gmail dot com
Description:
------------
is_callable(), with _syntax_only_ activated, only checks the type of the argument, not the actual
syntax. For example "+{^not&a*callable}" is considered a callable just because it is a
string.
I saw this bug report: https://bugs.php.net/bug.php?id=64185&edit=2,
and I get it for class names, but what about function/method names?
"+{^not&a*callable}" is definitely not a callable, or the parameter
"syntax_only" is incredibly misleading.
Test script:
---------------
var_dump(is_callable('+{^not&a*callable}', true, $callable_name));
var_dump($callable_name);
var_dump(is_callable(123, true));
var_dump(is_callable("123", true));
var_dump(is_callable([ "1", "2" ], true));
Expected result:
----------------
"+{^not&a*callable}" shouldn't be considred as a callable, neither
should [ "1", "2" ].
bool(false)
null
bool(false)
bool(false)
bool(false)
Actual result:
--------------
bool(true)
string(18) "+{^not&a*callable}"
bool(false)
bool(true)
bool(true)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70088&edit=1