Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called
| From: | Andi Gutmans | Date: | Thu, 22 Jun 2000 22:41:58 +0000 |
| Subject: | Re: PHP 4.0 Bug #5152: Object passed in a session generateserrors when member functions are called | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-22015@lists.php.net to get a copy of this message | ||
At 12:34 AM 6/23/00 +0200, Sascha Schumann wrote:
On Fri, 23 Jun 2000, Stanislav Malyshev wrote:I was just about to mention this as a very good solution to the problem. Yay Sascha. Andi --- Andi Gutmans <andi@zend.com> http://www.zend.com/SS>> Great. I'm +1 for going this route then. If there are no SS>> other proposals which do not add complexity (be it SS>> namespaces, serializing class definitions, etc), we can stop SS>> the discussion here.Please don't do it only this way. I feel like I'm preaching to the choir, but please think again: why at all you need to put this object in user-visible space?I've answered that question before.Just detect that object has that "strange" class, and don't do PS_ADD_VAR on it, do PS_HIDE_IT instead. You still need special class for this, maybe. But this class doesn't need to do anything - nobody will ever see any object of this class. OK, you can even add bailout on every function of that class, in case some smartass finds way to call it. But you don't really need to. Put please, don't tempt users into messing with data of objects which class is not defined. Just because $obj->data of class "foo" is not the same as $obj->data of class "bar", and there's no way to tell which type of object you've got (they are all stdSessionClass now).We can overwrite handle_property_get and handle_property_set, so that users cannot access properties. This would yield an appropiate error description as well.