Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called
| From: | Shane Caraveo | Date: | Wed, 21 Jun 2000 22:16:36 +0000 |
| Subject: | Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-21937@lists.php.net to get a copy of this message | ||
> We agree on:
>
> - PHP needs to preserve the name of the class of a
> serialized object, even if the class definition is not
> available during deserialization.
Why agree on that?
> We do not agree on:
>
> - PHP must stop script execution and output a misleading
> error message, if the script defines a class and if this
> class was absent on one or more object instantiations.
Why not agree on this?
I've been reading this thread and this seems fairly easy to deal with.
Currently, as I understand it, the "correct" way to do this is to
include any classes you are using prior to getting your session
variables back.
Based on that understanding, I think the apropriate way to handle this
is to give an error if a serialized class does not exist when it is
unserialized. This will force the programmer to include the file that
defines that class prior to unserializing the data.
Here is the reason I feel throwing an error is correct. Lets forget
about serializing for a moment, and just deal with plain ol php
scripting.
I have mystuff.inc which defines a class called myclass.
I have mypage.php which uses myclass.
If mypage.php does not include mystuff.inc, php will give an error,
becuase myclass is undefined. At that point, I must include mystuff.inc
(prior to using myclass) to get my script to work correctly. If php
simply decided to change myclass to stdclass, gee, it COULD be hellish
to debug if I simply forgot to include a file.
Now, why should it be any different when I unserialize data? If I
serialize myclass in mypage.php, then unserialize it in mypage2.php, but
mypage2.php does not include mystuff.inc, it should give an error.
The problem is, php is trying to be TOO SMART(TM) in how it handles this
situation by changing the class to stdclass, so that my script doesnt
break because I was too brainless to include the appropriate file(s)
prior to unserializing my data. Ease of use is one thing, but second
guessing what I am trying to do is another.
Throwing an error that says "ERROR: unserialized class XXX not defined"
would let me know that I need to include the file that defines that
class. You can also then do away with the stdclass thingy. This error
can be thrown from the unserialize function instead of having that
function change it to stdclass.
To me, this is the only SENSIBLE THING(TM) to do.
Shane
ps. never done this (TM) thing, kind of fun.