Re: [RFC] Deprecate the extract function in PHP 7.3
| From: | Stanislav Malyshev | Date: | Fri, 15 Sep 2017 21:59:13 +0000 |
| Subject: | Re: [RFC] Deprecate the extract function in PHP 7.3 | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-100656@lists.php.net to get a copy of this message | ||
Hi!
On 9/15/17 2:20 PM, ilija.tovilo@me.com wrote:
>> no, as there is no special risks
>
> There certainly is. No other function (as far as I’m aware) mutates your
> local symbol table. This means you need to know exactly what symbols are
Sure, because this is the function to mutate your local symbol table!
Why would we need more of them? It's like saying unlink() should be
removed because it deletes files and no other function does it, so it's
super-dangerous!
> defined and what kind of data you’ll receive when calling
extractW(nåiZ(!
> À“´Փ. So
> basically this is only safe right at the beginning of your function, and
> even then it can override your other parameters. Even with trusted data
> this can hardly be considered safe.
It does exactly what you tell it to do. Extracts array into local symbol
table. If you don't need that, don't use that function.
--
Stas Malyshev
smalyshev@gmail.com