Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called

From: Date: Thu, 22 Jun 2000 22:34:35 +0000
Subject: Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-22014@lists.php.net to get a copy of this message
On Fri, 23 Jun 2000, Stanislav Malyshev wrote: > SS>> Great. I'm +1 for going this route then. If there are no > SS>> other proposals which do not add complexity (be it > SS>> namespaces, serializing class definitions, etc), we can stop > SS>> the discussion here. > > Please don't do it only this way. I feel like I'm preaching to the choir, > but please think again: why at all you need to put this object in > user-visible space? I've answered that question before. > Just detect that object has that "strange" class, and > don't do PS_ADD_VAR on it, do PS_HIDE_IT instead. You still need special > class for this, maybe. But this class doesn't need to do anything - nobody > will ever see any object of this class. OK, you can even add bailout on > every function of that class, in case some smartass finds way to call > it. But you don't really need to. > > Put please, don't tempt users into messing with data of objects which > class is not defined. Just because $obj->data of class "foo" is not the > same as $obj->data of class "bar", and there's no way to tell which type > of object you've got (they are all stdSessionClass now). We can overwrite handle_property_get and handle_property_set, so that users cannot access properties. This would yield an appropiate error description as well. - Sascha

« previous php.dev (#22014) next »