#26946 [Opn]: casting an object instance to array exports protected/private data
| From: | helly@php.net | Date: | Thu, 05 Feb 2004 21:53:50 +0000 |
| Subject: | #26946 [Opn]: casting an object instance to array exports protected/private data | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-54479@lists.php.net to get a copy of this message | ||
ID: 26946
Updated by: helly@php.net
Reported By: andrey@php.net
Status: Open
Bug Type: Zend Engine 2 problem
Operating System: *
PHP Version: 5CVS-2004-01-17 (dev)
New Comment:
The solution is to manually loop through the property hash table and
return properties only with respect to visibility like we do inside
FE_FETCH opcode handler.
Previous Comments:
------------------------------------------------------------------------
[2004-01-17 11:12:18] andrey@php.net
Description:
------------
casting an object to array gives the possibility to get the values of
protected/private member variables :
IMO, when casting to array with (array) only the public-ly visible
members should returned.
Andrey
Reproduce code:
---------------
<?php
class some {
public $pub = 1;
protected $prot = 2;
private $priv = 3;
}
var_dump((array)new some());
?>
Expected result:
----------------
array(3) {
["pub"]=>
int(1)
}
Actual result:
--------------
array(3) {
["pub"]=>
int(1)
["*prot"]=>
int(2)
["somepriv"]=>
int(3)
}
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=26946&edit=1