[php-src] Issue #8296: Numeric casts must emit a warning it they do not make sense
| From: | bwoebi | Date: | Thu, 07 Apr 2022 10:08:34 +0000 |
| Subject: | [php-src] Issue #8296: Numeric casts must emit a warning it they do not make sense | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-240729@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8296
Comment Author: bwoebi
While we warn when casting an array to a string, this is about preventing the whole class of arrays,
and not specific patterns of arrays (like with strings where numerical ones would be allowed).
To get a checked cast of a string to a number, I'd recommend the one-char variant, prepending a
+ sign. Given that there is a short way to do a checked conversion to number (plus
sign) - and a longer (the cast) unchecked version, I do not think there's a need for a change.
In fact it's a good thing that there exists a (relatively easy) way to do unchecked casts
"just squeeze that into a number". It's a safe way of doing that which existed since
very old times and should stay.
A common use case for int casts is taking (possibly client-side validated) user inputs for example.
You do not really want to break this common scenario.