Re: Deprecate PHP's short open tags, again
| From: | Robert Korulczyk | Date: | Wed, 14 Aug 2019 13:19:38 +0000 |
| Subject: | Re: Deprecate PHP's short open tags, again | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-106601@lists.php.net to get a copy of this message | ||
W dniu 14.08.2019 o 14:14, Reinis Rozitis pisze:
> Depends on how you look at if exec($_GET['param']) is a language responsibility or
> programmers?
Please, let's keep this discussion at some level of sanity... You basically need stick to
static HTML if you're considering possibility of such exec()
usage as a security issue.
They're at least 3 main deferences between short open tags and exec-like functions:
1. exec-like functions have their purpose without any straight-forward alternative, while
<? is just worse version of <?php.
2. exec($_GET['param']) is not intended usage of exec() while
<? $dbPasword = 'my$ecret' ?> is intended usage of short open tags.
3. Because of point 2, there is no IDE or editor which will generate code like
exec($_GET['param']), while there is at least one popular IDE which
will generate code with short open tags.
Regards,
Robert Korulczyk