Bug #75348 [Opn]: Private/protected property disclosure
| From: | googleguy@php.net | Date: | Tue, 10 Oct 2017 04:07:05 +0000 |
| Subject: | Bug #75348 [Opn]: Private/protected property disclosure | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211593@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75348&edit=1
ID: 75348
Updated by: googleguy@php.net
Reported by: anrdaemon at freemail dot ru
Summary: Private/protected property disclosure
Status: Open
Type: Bug
Package: *General Issues
Operating System: All
PHP Version: 7.2.0RC3
Block user comment: N
Private report: N
New Comment:
The array pointer functions really should just throw a type error here instead of blindly casting
the object to an array. HHVM gets it right, why shouldn't we? I thought we were supposed to
more aligned in implementation.
Previous Comments:
------------------------------------------------------------------------
[2017-10-10 03:58:31] anrdaemon at freemail dot ru
Description:
------------
It is possible to access values (and names to an extent) of all object properties regardless their
access level using reset/end/each.
This behavior also prevents the expected behavior from using reset/next/current with clasess
implementing Iterator/ArrayAccess interfaces.
Test script:
---------------
<?php
class MyClass
{
private $var1 = 'Some value 1';
protected $var2 = 'Some value 2';
protected $var3 = 'Some value 3';
}
$obj = new MyClass;
foreach($obj as $key => $value)
{
print "$key => $value\n";
}
reset($obj);
while($val = each($obj)) print_r($val);
Expected result:
----------------
No output.
Actual result:
--------------
The class content is dumped from second loop.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75348&edit=1