Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called
| From: | Sascha Schumann | Date: | Thu, 22 Jun 2000 22:34:35 +0000 |
| Subject: | Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-22014@lists.php.net to get a copy of this message | ||
On Fri, 23 Jun 2000, Stanislav Malyshev wrote:
> SS>> Great. I'm +1 for going this route then. If there are no
> SS>> other proposals which do not add complexity (be it
> SS>> namespaces, serializing class definitions, etc), we can stop
> SS>> the discussion here.
>
> Please don't do it only this way. I feel like I'm preaching to the choir,
> but please think again: why at all you need to put this object in
> user-visible space?
I've answered that question before.
> Just detect that object has that "strange" class, and
> don't do PS_ADD_VAR on it, do PS_HIDE_IT instead. You still need special
> class for this, maybe. But this class doesn't need to do anything - nobody
> will ever see any object of this class. OK, you can even add bailout on
> every function of that class, in case some smartass finds way to call
> it. But you don't really need to.
>
> Put please, don't tempt users into messing with data of objects which
> class is not defined. Just because $obj->data of class "foo" is not the
> same as $obj->data of class "bar", and there's no way to tell which type
> of object you've got (they are all stdSessionClass now).
We can overwrite handle_property_get and handle_property_set,
so that users cannot access properties. This would yield an
appropiate error description as well.
- Sascha