Re: Taint mode for PHP
| From: | PHP | Date: | Thu, 06 Jul 2000 00:34:52 +0000 |
| Subject: | Re: Taint mode for PHP | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-5117@lists.php.net to get a copy of this message | ||
> > Is there a way to require that all script variables be declared before they
> > can be used? Sort of like taint mode in Perl. Would also be nice if the
> > parser spit back an informative error for all undeclared variables.
>
> Crank your error_reporting level way up. ie. set it to E_ALL in your
> php.ini file.
>
> -Rasmus
It looks like E_ALL just requires that variables have assignments made
before they used in a statement. This is not quite what I would like.
What I would like is that the parser would issue a warning for height but not
width in the code below. If is did, then the would assist in catching bugs
associated with missspelled variable names. These can be nasty errors to
track down in some cases.
<?php
error_reporting(E_TAINT); // made this up
var $width;
$height = 5; // warning issued - $height is not declared.
$width = $height * 2;
?>
Regards,
Paul Meagher