#26946 [Ver]: casting an object instance to array exports protected/private data
| From: | andrey@php.net | Date: | Mon, 15 Mar 2004 15:33:02 +0000 |
| Subject: | #26946 [Ver]: casting an object instance to array exports protected/private data | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-56499@lists.php.net to get a copy of this message | ||
ID: 26946
User updated by: andrey@php.net
Reported By: andrey@php.net
Status: Verified
Bug Type: Zend Engine 2 problem
Operating System: *
PHP Version: 5CVS-2004-03-15
New Comment:
But print_r()'s output has to be parsed while a simple cast is enough
to get the data straightly.
Previous Comments:
------------------------------------------------------------------------
[2004-03-15 10:29:46] sniper@php.net
print_r() shows them too, even without the cast..
------------------------------------------------------------------------
[2004-02-05 16:53:50] helly@php.net
The solution is to manually loop through the property hash table and
return properties only with respect to visibility like we do inside
FE_FETCH opcode handler.
------------------------------------------------------------------------
[2004-01-17 11:12:18] andrey@php.net
Description:
------------
casting an object to array gives the possibility to get the values of
protected/private member variables :
IMO, when casting to array with (array) only the public-ly visible
members should returned.
Andrey
Reproduce code:
---------------
<?php
class some {
public $pub = 1;
protected $prot = 2;
private $priv = 3;
}
var_dump((array)new some());
?>
Expected result:
----------------
array(3) {
["pub"]=>
int(1)
}
Actual result:
--------------
array(3) {
["pub"]=>
int(1)
["*prot"]=>
int(2)
["somepriv"]=>
int(3)
}
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=26946&edit=1