Bug #70088 [Opn]: is_callable() doesn't check if a class/method syntax is valid

From: Date: Thu, 16 Jul 2015 13:50:39 +0000
Subject: Bug #70088 [Opn]: is_callable() doesn't check if a class/method syntax is valid
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194492@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70088&edit=1 ID: 70088 User updated by: olivier dot laviale at gmail dot com Reported by: olivier dot laviale at gmail dot com Summary: is_callable() doesn't check if a class/method syntax is valid Status: Open Type: Bug Package: Scripting Engine problem Operating System: MacOS, Linux PHP Version: 5.6.11 Block user comment: N Private report: N New Comment: Yes, you can invoke methods with invalid names if __call() is implemented, I don't think it's right, but that's a fact. My point is that the following code should return false: var_dump(is_callable('+{^not&a*callable}', true, $callable_name)); Unless '+{^not&a*callable}' is a valid function name. Also, I strongly believe that "syntax_only" is misleading. This is not syntax check, this is type check: a string, or an array with two values. Previous Comments: ------------------------------------------------------------------------ [2015-07-16 13:33:05] ab@php.net Maybe it could be improved if we check whether an object has __call() defined. But if it has __call() - there's no chance to know exactly what is callable, say this would work $obj->{"+{^not&a*callable}"}();. But I'd rather tend to say it is not a bug. Thanks. ------------------------------------------------------------------------ [2015-07-16 12:53:41] olivier dot laviale at gmail dot com Description: ------------ is_callable(), with _syntax_only_ activated, only checks the type of the argument, not the actual syntax. For example "+{^not&a*callable}" is considered a callable just because it is a string. I saw this bug report: https://bugs.php.net/bug.php?id=64185&edit=2, and I get it for class names, but what about function/method names? "+{^not&a*callable}" is definitely not a callable, or the parameter "syntax_only" is incredibly misleading. Test script: --------------- var_dump(is_callable('+{^not&a*callable}', true, $callable_name)); var_dump($callable_name); var_dump(is_callable(123, true)); var_dump(is_callable("123", true)); var_dump(is_callable([ "1", "2" ], true)); Expected result: ---------------- "+{^not&a*callable}" shouldn't be considred as a callable, neither should [ "1", "2" ]. bool(false) null bool(false) bool(false) bool(false) Actual result: -------------- bool(true) string(18) "+{^not&a*callable}" bool(false) bool(true) bool(true) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70088&edit=1

« previous php.bugs (#194492) next »