Re: PHP 4.0 Bug #7749: addslashes wrong thing to do
| From: | James Ponder | Date: | Fri, 10 Nov 2000 22:30:42 +0000 |
| Subject: | Re: PHP 4.0 Bug #7749: addslashes wrong thing to do | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-37719@lists.php.net to get a copy of this message | ||
On Fri, Nov 10, 2000 at 11:34:49AM -0600, Andrei Zmievski wrote:
>> The first thing to note here is that the idea of substituting into
>> the replacement string like this was a very bad idea, I would encourage
>> you to phase this out in favour of $<num> replacement.
>
> Could, but then what about backwards compatibility?
That's for you to work out. A suggestion springs to mind - if $<num> has
no special meaning currently, mark it as reserved in the documentation, then
after a year or so, set \<num> and $<num> for another year, then two
years later remove \<num>. The last stage doesn't even need to happen,
just so long as the documentation says it is prefered to use $<num>.
> What if the match contains " and your expression looks like
> 'length("\\2")'? Both " and ' need to be escaped.
Yes, it is true that if you do length("\\2") then " needs to be escaped,
and this is why you need to specify in your documentation what you expect
the user to do. It is undocumented whether you should use " or ', infact
it's just plain undocumented that PHP will do anything magic with it at all.
The documentation has an example where ''s are used, therefore I say
that any reader of any worth is going to know that you MUST quote or there
will be security problems, and since they'll know that ''s and ""s are
different, will presume that using ""s is wrong.
> The point was to make it easy for people used to Perl's regex syntax.
Maybe, but it was still a mistake. It's a bad thing in Perl that you have
to think of a character that isn't in the regexp string. The PHP
developers have effectively added a feature that even Perl users don't
want and would get rid of if they could.
Best wishes, James
--
James Ponder; www.squish.net