#26946 [Ver]: casting an object instance to array exports protected/private data

From: Date: Mon, 15 Mar 2004 15:33:02 +0000
Subject: #26946 [Ver]: casting an object instance to array exports protected/private data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-56499@lists.php.net to get a copy of this message
ID: 26946 User updated by: andrey@php.net Reported By: andrey@php.net Status: Verified Bug Type: Zend Engine 2 problem Operating System: * PHP Version: 5CVS-2004-03-15 New Comment: But print_r()'s output has to be parsed while a simple cast is enough to get the data straightly. Previous Comments: ------------------------------------------------------------------------ [2004-03-15 10:29:46] sniper@php.net print_r() shows them too, even without the cast.. ------------------------------------------------------------------------ [2004-02-05 16:53:50] helly@php.net The solution is to manually loop through the property hash table and return properties only with respect to visibility like we do inside FE_FETCH opcode handler. ------------------------------------------------------------------------ [2004-01-17 11:12:18] andrey@php.net Description: ------------ casting an object to array gives the possibility to get the values of protected/private member variables : IMO, when casting to array with (array) only the public-ly visible members should returned. Andrey Reproduce code: --------------- <?php class some { public $pub = 1; protected $prot = 2; private $priv = 3; } var_dump((array)new some()); ?> Expected result: ---------------- array(3) { ["pub"]=> int(1) } Actual result: -------------- array(3) { ["pub"]=> int(1) ["*prot"]=> int(2) ["somepriv"]=> int(3) } ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=26946&edit=1

« previous php.bugs (#56499) next »