Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called

From: Date: Thu, 22 Jun 2000 22:41:58 +0000
Subject: Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-22015@lists.php.net to get a copy of this message
At 12:34 AM 6/23/00 +0200, Sascha Schumann wrote:
On Fri, 23 Jun 2000, Stanislav Malyshev wrote:
SS>>     Great. I'm +1 for going this route then. If there are no
SS>>     other proposals which do not add complexity (be it
SS>>     namespaces, serializing class definitions, etc), we can stop
SS>>     the discussion here.
Please don't do it only this way. I feel like I'm preaching to the choir, but please think again: why at all you need to put this object in user-visible space?
    I've answered that question before.
Just detect that object has that "strange" class, and don't do PS_ADD_VAR on it, do PS_HIDE_IT instead. You still need special class for this, maybe. But this class doesn't need to do anything - nobody will ever see any object of this class. OK, you can even add bailout on every function of that class, in case some smartass finds way to call it. But you don't really need to. Put please, don't tempt users into messing with data of objects which class is not defined. Just because $obj->data of class "foo" is not the same as $obj->data of class "bar", and there's no way to tell which type of object you've got (they are all stdSessionClass now).
    We can overwrite handle_property_get and handle_property_set,
    so that users cannot access properties. This would yield an
    appropiate error description as well.
I was just about to mention this as a very good solution to the problem. Yay Sascha. Andi --- Andi Gutmans <andi@zend.com> http://www.zend.com/

« previous php.dev (#22015) next »