Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called

From: Date: Wed, 21 Jun 2000 22:16:36 +0000
Subject: Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-21937@lists.php.net to get a copy of this message
> We agree on: > > - PHP needs to preserve the name of the class of a > serialized object, even if the class definition is not > available during deserialization. Why agree on that? > We do not agree on: > > - PHP must stop script execution and output a misleading > error message, if the script defines a class and if this > class was absent on one or more object instantiations. Why not agree on this? I've been reading this thread and this seems fairly easy to deal with. Currently, as I understand it, the "correct" way to do this is to include any classes you are using prior to getting your session variables back. Based on that understanding, I think the apropriate way to handle this is to give an error if a serialized class does not exist when it is unserialized. This will force the programmer to include the file that defines that class prior to unserializing the data. Here is the reason I feel throwing an error is correct. Lets forget about serializing for a moment, and just deal with plain ol php scripting. I have mystuff.inc which defines a class called myclass. I have mypage.php which uses myclass. If mypage.php does not include mystuff.inc, php will give an error, becuase myclass is undefined. At that point, I must include mystuff.inc (prior to using myclass) to get my script to work correctly. If php simply decided to change myclass to stdclass, gee, it COULD be hellish to debug if I simply forgot to include a file. Now, why should it be any different when I unserialize data? If I serialize myclass in mypage.php, then unserialize it in mypage2.php, but mypage2.php does not include mystuff.inc, it should give an error. The problem is, php is trying to be TOO SMART(TM) in how it handles this situation by changing the class to stdclass, so that my script doesnt break because I was too brainless to include the appropriate file(s) prior to unserializing my data. Ease of use is one thing, but second guessing what I am trying to do is another. Throwing an error that says "ERROR: unserialized class XXX not defined" would let me know that I need to include the file that defines that class. You can also then do away with the stdclass thingy. This error can be thrown from the unserialize function instead of having that function change it to stdclass. To me, this is the only SENSIBLE THING(TM) to do. Shane ps. never done this (TM) thing, kind of fun.

« previous php.dev (#21937) next »